Yealink T29G - Web GUI certificate warnings after 18.6 & firmware update.

Status
Not open for further replies.

KrisEiT

Silver Partner
Advanced Certified
Joined
Jul 26, 2022
Messages
23
Reaction score
7
Hi All,
I'm hoping someone might be able to help me out, we have a customer running a mixture of T2x & T4x phones who has reported some strange accessibility issues getting to the web GUI on phones, the PBX was recently upgraded to 18.6 and after completing this it highlighted a number of phones needed newer firmware versions, our customer proceeded to upgrade the phones and has now noticed that on some phones when he tries to load the web gui he gets a warning in Chrome that he cannot proceed past (see image below), other phones appear to work fine.

I've noticed that on the phones with the issue they appear to be missing two certificates from the list of installed certs, but after factory resetting & re-provisioning the phone it still doesn't get these certs and still causes chrome to generate the warning about an invalid cert that cannot be bypassed.



ew_error.PNG
ew_error1.PNG
 

Attachments

  • ew_error.PNG
    ew_error.PNG
    186.2 KB · Views: 2
I don't have the solution, but one sneaky workaround that may help in the meantime is that you can proceed past chrome's security warnings by typing in thisisunsafe (there's no place to type it in, just have faith).
 
thisisunsafe
I've run into that on Chrome at least a couple of times in the last year as well, though not on phones...one I know was a router with a self signed cert (like the phones). Also, IIRC Firefox doesn't stop like that, it still lets you proceed...as Chrome normally does.
other phones appear to work fine
Could that Chrome have accepted that phone's cert in the past?
 
Hi Kris,

It's not the device upgrade, or the PBX upgrade - it's in fact the browser. As browsers become more secure and older devices no longer meet their strict security policies, this will become more prevalent. I don't think this can be avoided given the nature of these things.

Feel free to contact Yealink if you want more details, but I would not expect them to overhaul the firmware of older devices to keep up with modern browser standards.
 
Hi Kris,

It's not the device upgrade, or the PBX upgrade - it's in fact the browser. As browsers become more secure and older devices no longer meet their strict security policies, this will become more prevalent. I don't think this can be avoided given the nature of these things.

Feel free to contact Yealink if you want more details, but I would not expect them to overhaul the firmware of older devices to keep up with modern browser standards.
Hi John, normally I'd have no issue and agree with you on this but the strange part here is that out of all the older phones that got the new firmware update Chrome isn't blocking access to them all, just a random selection of phones get the cert error we can't bypass some of them work perfectly fine and without issue in chrome. which is what made me think its a provisioning issue due to some phones missing the certificates but so far we'd found that regardless of the certs some phones can be managed others can't.

Using MS Edge to access any of the phones works fine and he can manage them all, it only seems to be a problem for some phones in Chrome & Firefox.
 
which is what made me think its a provisioning issue due to some phones missing the certificates
But we don't provision any certificates into the phones and never have - they use whatever Yealink has built into the firmware.

Not sure we can provide any answers as to why one company's browser doesn't work on another company's phone, this is entirely out of our scope :p

One thing that might make the difference: notice whether you are contacting the phone over plain http or HTTPS.
 
cert error we can't bypass
Is your error page the one from @SnakeRiverWebDevelopment's link above? Type "thisisunsafe" into the web page (there is no prompt, just type the characters) and Chrome will bypass its warning. I've seen that in Chrome to a self-signed or unrecognized cert from some PCs and not others (to routers, not to phones). ¯\_(ツ)_/¯
 
Status
Not open for further replies.

Members Online Now

Forum statistics

Threads
111,832
Messages
589,285
Members
164,662
Latest member
DejanMDS