Windows App not connecting with SIP-Transport set to TLS

Status
Not open for further replies.

Alex_N

Forum User
Joined
Apr 18, 2019
Messages
38
Reaction score
4
Hello,

as you can read in the title my Windows App Client doesn't log in when I set the SIP-Transport to TLS.

More information about the environment:
3cx PBX is installed on a Linux server hosted in the Google Cloud (external) with an own FQDN using a buy certificate from domainfactory.
In the pbx under settings -> security -> secure SIP -> I also activated Secure SIP and filled in the certificate + key fields.
I checked the firewall, don't see any problems there. I can see that my computer tries to connect with port 5061 which is green highlighted on the firewall so it allows the connection.
I also used a notebook gave it wifi hotspot from my smartphone (so there is no firewall in between) and it still doesn't work.


Do you have any idea why it doesn't work?

Greetings and thanks,

Alex
 
Last edited:
No need for TLS has the app uses the tunnel which is already encrypted.
 
Where did you get your certificate detail from?

Are you using 3CX FQDN or custom?

Did you follow this https://www.3cx.com/docs/secure-sip/

have you imported certificates in to the PC?
 
No need for TLS has the app uses the tunnel which is already encrypted.
Yes, I know that but I still want to make it work with TLS. Reason is that I am doing a project work and I want to try out everything and make it work for my documentation.
 
Yes, I know that but I still want to make it work with TLS. Reason is that I am doing a project work and I want to try out everything and make it work for my documentation.
I never made it work since V16. V15.5 used to work but now it doesn't. Neither the apps nor a phone work correctly when using SIPS. It is not supported at the moment.
 
I never made it work since V16. V15.5 used to work but now it doesn't. Neither the apps nor a phone work correctly when using SIPS. It is not supported at the moment.
I sit the whole day trying things out to make it work and now I get the information it is not supported at the moment. :) If that is true why the 3cx team dont edit the documentation about secure sip.
https://www.3cx.com/docs/secure-sip/

If a mod reads this do you have any information if this will soon get fixed? Luckily I have three months time.
 
I sit the whole day trying things out to make it work and now I get the information it is not supported at the moment. :) If that is true why the 3cx team dont edit the documentation about secure sip.
https://www.3cx.com/docs/secure-sip/

If a mod reads this do you have any information if this will soon get fixed? Luckily I have three months time.
Well, that document has been updated recently because it was different before.

Like the doc explains tho, the apps don't need Secure SIP and to be honest, it's probably not good to have TLS over TLS (since the Tunnel is already TLS encrypted).

If you have a deskphone tho, try it I am curious.
 
Right now I am only trying it out with Softphone.
The doc explains it particularly for mobile apps. So the windows App is mobile? I thought it means iOS and Android.
I wouldn't do TLS over TLS because I turned the tunnel off. (just for testing purposes, of course it is always easier and better to use the tunnel)

It is only one sentence(not even highlighted) hidden in a wall of text that suggests that Secure SIP is not working so it means the whole instruction is obsolute.
 
certificates are from: https://www.df.eu/
custom FQDN
yes followed this but it's a linux server not windows.
Yes i've imported the certificates to the pc also it is not needed.
What makes you think Windows doesnt need the certificates

14134
 
  • Like
Reactions: Evolute IT
Right now I am only trying it out with Softphone.
The doc explains it particularly for mobile apps. So the windows App is mobile? I thought it means iOS and Android.
I wouldn't do TLS over TLS because I turned the tunnel off. (just for testing purposes, of course it is always easier and better to use the tunnel)

It is only one sentence(not even highlighted) hidden in a wall of text that suggests that Secure SIP is not working so it means the whole instruction is obsolute.
The app reprovision itself from the 3CX so you need to disable the tunnel and set TLS on the 3CX App page under Extension > Phone Provisioning.

Have you added your root certificate to Windows like explained in the doc?
 
What makes you think Windows doesnt need the certificates

View attachment 14134
"and picked a self-signed or unstrusted certificate from an unknown rooth authority"
My certificate is neither self-signed or unstrusted.
It is an alpha ssl certificate which is widely accepted.

But just to be sure I also imported it into my windows.
 
  • Like
Reactions: Evolute IT
What is your use-case for Secure SIP?

If simply for encryption, use the tunnel. For phones, use an SBC.
 
The app reprovision itself from the 3CX so you need to disable the tunnel and set TLS on the 3CX App page under Extension > Phone Provisioning.

Have you added your root certificate to Windows like explained in the doc?
I turned the auto provisioning offline. So it doesn't take the configuration from the PBX automatically.
And yes I set TLS on my extension.
 
What is your use-case for Secure SIP?

If simply for encryption, use the tunnel. For phones, use an SBC.
As far as I know the tunnel uses an encryption but it is not clearly which encryption exactly is actually used.
I just wanted to make it work with Secure SIP TLS Transport method since I am also doing a documentation work for a project.
 
As far as I know the tunnel uses an encryption but it is not clearly which encryption exactly is actually used.
I just wanted to make it work with Secure SIP TLS Transport method since I am also doing a documentation work for a project.
The tunnel uses a special TLS encryption. No, they won't tell because it adds security by obfuscation.

AFAIK, 3CX won't support Secure SIP for now. It might work, but you won't get support if issues arise. I wouldn't spend too much time on it.

Stick with the tunnel for encryption needs. For deskphones, use a VPN or the SBC.
 
  • Like
Reactions: Alex_N
Yes, I am done with this topic, thank you for the information. Who knows how many hours I would have spent more in a thing that is not even supported anymore if you didn't tell me.

And yes for deskphones we are already using a SBC.
 
  • Like
Reactions: Evolute IT
Status
Not open for further replies.

Forum statistics

Threads
112,025
Messages
590,367
Members
164,976
Latest member
Roman Mazur