Windows Client SSL

Status
Not open for further replies.

Simonutley

Customer
Intermediate Cert.
Joined
Jan 17, 2018
Messages
11
Reaction score
2
Hi All,

Bit of help needed!

Background setup - 3CX hosted extenrally, internal site has a VPN site to site and works fine. I have tried to implement SSIP which works great with the cert no issues.

The issue i am having is that i have a remote handset setup via STUN which registers on 5061 no issues but, when i try to setup the windows client on my pc and provision the client to 5061, it will not regsiter. The logs seem to point to an SSL issue? See below.

[13.07.2018 12:30:36.748][17] 12:30:36.748 pjsua_acc.c .Acc 2: Registration sent
[13.07.2018 12:30:36.748][17] pjsua_acc_set_registration returned 0
[13.07.2018 12:30:36.892][17] 12:30:36.891 pjsua_acc.c Disconnected notification for transport tlsc08832894
[13.07.2018 12:30:36.892][17] 12:30:36.892 tlsc08832894 TLS connect() error: SSL certificate verification error (PJSIP_TLS_ECERTVERIF)

The same cert is installed on the handset and my pc so, i'm not sure why i would get this issue?

Any ideas?

Cheers
 
Hello @Simonutley

Are you using a 3CX FQDN or a custom one? If you are using a 3CX FQDN do the following:

Navigate to Extension settings / Phone Provisioning tab and select the 3CX client from the drop down list.
Select the FQDN under the provisioning interface.
Set the SIP transport to TLS
Set the RTP mode to Allow secure (optional)
Disable option "Use 3CX Tunnel for remote connections (3CX Client only)"

Then navigate to the options tab and un-tick the option "Disallow use of extension outside the LAN (Remote extensions using Direct SIP or STUN will be blocked)"

Send a new welcome email to the client and it should register.

If you are using a custom FQDN you will need to import the certificate to your machine first if not already trusted.
 
Hi @YiannisH_3CX,

I am using a custom FDQN which is all correct and working.

I have provisioned the 3CX client as you have said above and imported the correct certificate on to my pc in Trusted CA root and then tried to provision the client.

I still get the error "Register Failed, Service Unavailable" - then relates back to my earlier screenshot of the 3cx client error log.

In the client > account options > "My Location" i have in both fields my custom FDQN:5061. I've made sure the Tunnel password is correct.

Are there any other settings? My setup at the minute is that i am "out of the office".

Thank you
 
In the client > account options > "My Location" i have in both fields my custom FDQN:5061. I've made sure the Tunnel password is correct.
As i mentioned you need to disable the tunnel for these extensions if you need to register through TLS.
 
I have reprovisioned the phone without tunnel port option and it still will not register - same error. Antivirus has been disabled also.

Any other ideas?
 
If this is a certificate issue on the client machine then there is really not much we can do from the PBX side. The only thing i can recommend at this point is trying the same test with a PBX using a 3CX FQDN and see if that works for you.
 
Status
Not open for further replies.

Forum statistics

Threads
112,025
Messages
590,365
Members
164,976
Latest member
Roman Mazur