Upgrade to v15.5 for new SSL certs!

Status
Not open for further replies.

mctcondez

Free User
Advanced Certified
Joined
Jul 27, 2018
Messages
14
Reaction score
3
Hi All,

Hope someone in the community can clarify this inquiry.

We recently received a notification from 3cx, see below:

------------------------------------------------------------------------------------------------------------------------------------------
You are currently running an outdated version of 3CX and we are happy to see you are still enjoying it. However, since you first downloaded 3CX, we have released a number of new features and security updates. Now is the perfect time to upgrade to the latest version, v15.5, see why below.

3CX license reactivation will fail
On September 15th, 3CX will update the certificates which are required to activate 3CX products. This change is due to numerous reasons. Firstly, the SSL certificates will expire on this date and also there is a conflict between Mozilla/Google and the certificate issuer.

If you try to reactivate your current installation for any reason, reactivation will fail. If you do not upgrade, and you make any changes to the hardware or to the public IP, the PBX will revert to free mode after this date. YOU MUST UPGRADE ASAP!

------------------------------------------------------------------------------------------------------------------------------------------

Are we affected on this or it's notification for all?
By the way we have 3cx v15.5 (sp1) from one of our instance. And we use our own fqdn + SSL cert on our 3cx instance. Should we still update to the latest sp6 version? As its not clear what type of version requirement for said SSL update.

Regards,
Mark
 
I'm having the same doubt.
We are also running SP2, using our own FQDN and SSL cert that we bought.
 
Hopefully someone could shed a light about our issue
 
Hello,

Please note that all systems below V15.5 SP6 are affected by this as this has nothing to do with the certificates you used to install the system. The certificate that is expiring is the certificate of the Activation server. This means that when your PBX tries to reach activation server it will not recognise the new certificate and the activation will fail. That is why you need to upgrade to the latest version where the new certificate is included to avoid this issue.
 
@YiannisH_3CX, Thank you for clarifying this issue. You are indeed an asset to this community.
 
Glad i could help and thank you for your kind comments.
 
  • Like
Reactions: accentlogic
Hello,

Please note that all systems below V15.5 SP6 are affected by this as this has nothing to do with the certificates you used to install the system. The certificate that is expiring is the certificate of the Activation server. This means that when your PBX tries to reach activation server it will not recognise the new certificate and the activation will fail. That is why you need to upgrade to the latest version where the new certificate is included to avoid this issue.

So, are you saying that we have to upgrade all our client instances to V15.5 SP6 by Sept 15th of this year (less than 2 weeks from now)? Why was more advance notification not provided about this issue? Why can't 3CX just renew the current certificates on the activation servers?

(Edit) Also, what will happen if/when the activation fails? Nevermind, I see above that is says it will revert to free version. This is really unacceptable that we are just being notified about this now!
 
We have been telling (in email mailings etc) users and partners alike to upgrade to 15.5 for YEARS. We decided that all 3CX users can upgrade FREE OF CHARGE to the latest edition. Not only that, you can start renewing your maintenance again from 30/10/2018. (i.e. no late penalty and no need to pay for the past - and only if you want) Should we have sent the mail a month earlier? Yes - and we apologize for that. It took time to plan and put together this offer. On the whole i think the options for customers are pretty positive.

Anybody on v15.5 can go to SP6 literally in MINUTES. v14 might take a little bit longer and very old versions of v11 or v12 a bit longer of course. Those versions are up to 5 years old, really not OK to leave them as they are.

Your system will continue to work after that date if you don't change anything such as re-install it or change the hard disk. So realistically you have more time than 15th September. We are also probably going to extend the date for another few weeks to give everybody more time. But its good practice to be prepared and update now.

Furthermore we are assisting larger users with free migration advice via our customer service email address. Partners already have free support and assistance.

To be secure on the internet you need to have your software up to date and upgrading should be done anyhow, independent of the certificates.
 
Last edited:
Nick, thank you for the clarification.

So if I leave my PBXs at v15.5 with SP 5, I am not in any trouble as long as I dont change the hardware? (they are all virtual private servers anyway)

And I have heard a provider saying that the update to Debian 9 also has to happen now. Is that correct?

Edit:
Let me clarify why I cant update to servicepack 6; our organisation has a patch day only once every 6 weeks. We just patched everything to servicepack 5 and I have to wait 4 more weeks to update everything to servicepack 6. It’s just a procedure thing and has been decided by the change management team (we are a large company and follow itil processes by the letter).
 
So if I leave my PBXs at v15.5 with SP 5, I am not in any trouble as long as I dont change the hardware? (they are all virtual private servers anyway)
This is not guaranteed as a network change could also trigger an activation of your PBX but since you are above V15.0 SP4 you have a small added window until October 15th before you are affected by the certificate change so you should have plenty of time to perform the upgrade. The 15th of October is not the last date but if something goes wrong this should give you a few extra days to repeat the process.

And I have heard a provider saying that the update to Debian 9 also has to happen now. Is that correct?
This is correct as the supported Debian version is Debian 9.
 
There still is one thing not clear for me. Upgrade is free to 15.5SP6.
Current instalations cannot work without maintenance paid, while it is OK for older versions of 3CX to work only with valid license.
Does it mean that you make your old customers to pay annual maintenance fee in order to leave their PBX work?
How long will work the freshly upgraded PBX-es, if the customer does not want to pay yearly fee?
 
This is not guaranteed as a network change could also trigger an activation of your PBX but since you are above V15.0 SP4 you have a small added window until October 15th before you are affected by the certificate change so you should have plenty of time to perform the upgrade. The 15th of October is not the last date but if something goes wrong this should give you a few extra days to repeat the process.


This is correct as the supported Debian version is Debian 9.
So if we have clients who are on V14 (on a multi-tenant server) and cannot move or upgrade because of contracts with the hosting provider and SIP provider, what are our options?
 
I'm trying to update someone on v15.0 and it won't let me. Nick said everyone can upgrade free of charge. Please explain how to upgrade.
I am getting the "Maintenance Expired. Updates not available" pop up.
 
@Dimitrov - all perpetual versions with active purchased licenses have had their maintenance extended and you can upgrade free of charge. Annual keys can be upgraded anyways as they dont require maintenance. You can contact customer support with the key in question.

@dkeethler - hosting or sip providers can also use v15.5 - should not really make a difference. Please contact customer support with your exact case and key.... You can upgrade free.
 
Does the update to Debian 9 need to happen manually or did the update to U6 trigger this automatically? If not, can you walk us through the steps needed to get on this version?
 
Does the update to Debian 9 need to happen manually or did the update to U6 trigger this automatically? If not, can you walk us through the steps needed to get on this version?

Hi Paul - the update does not happen automatically. Because this update is an OS Update.
So what happens is this.
First 3CX will update to update 6.
After this, if the OS is debian 8, you will see an OS Update available Debian 9.
You press a button (this is the manual part) and it updates.
 
@Dimitrov - all perpetual versions with active purchased licenses have had their maintenance extended and you can upgrade free of charge. Annual keys can be upgraded anyways as they dont require maintenance. You can contact customer support with the key in question.

@dkeethler - hosting or sip providers can also use v15.5 - should not really make a difference. Please contact customer support with your exact case and key.... You can upgrade free.
Nick,

We have clients on the Multi-Tenant v14 that we are planning to upgrade and migrate away from to their own v15.5 standalone server. However, they have a contract with the current hosting provider which also happens to be the SIP provider.

What do you propose we do?
 
@dkeethler

So that seems to be more of a business decision than anything. Not sure what the contract states but if there is the potential for service interruption then the provider either needs to have a plan to upgrade to v15 or they need to let your customer out of the contract for failure to perform. So not really a 3CX question.
 
@dkeethler

So that seems to be more of a business decision than anything. Not sure what the contract states but if there is the potential for service interruption then the provider either needs to have a plan to upgrade to v15 or they need to let your customer out of the contract for failure to perform. So not really a 3CX question.

Well 3CX is forcing an upgrade on several customers that may not be able to upgrade. That's why I want to hear from Nick. This customer's 3CX cannot move to another server or SIP provider. They are on a v14 multi-tenant instance. They are paying the hosting provider for hosting the server. Their contract is not over for several more months. I'd also like to know when 3CX made this decision. It's repeated, forced changes that drive customers away.
 
Sorry I think you may have misunderstood me. The hosting provider is under the same demands your customer is, so they either need to have a plan to upgrade or they need to release your customer from their contract so they can find a solution that won't potentially implode as staying with v14 multi-tenant will. As far as the 3CX decisions... well let's just say this isn't the first time the activation server changed and forced upgrades.
 
Status
Not open for further replies.

Forum statistics

Threads
112,095
Messages
590,732
Members
165,073
Latest member
sca-njw17