Certificate Management

I have been using Let’s Encrypt in my FreePBX for a long time now and it has been working fine so far, but last week it stopped working and the certificate is not renewed any more. I have the IP addresses of the following FQDN set in my firewall (port 80):

outbound1.letsencrypt.org, outbound2.letsencrypt.org, mirror1.freepbx.org, mirror2.freepbx.org

When I open port 80 to all addresses, the certificate is renewed without problems. Do I have to add (or change) the IP addresses?

Hi @vespino,
Pls check first your CertMan Module version.
| certman | 14.0.7 | Enabled | AGPLv3+ |

PBX and Router Firewall allows LE Port 80 and Port Forward 80 TCP to PBX IP address.
Then try to reproduce again. If not works pls open Support Ticket we will give you help.

Thanks.

@snazir does this help?

screenshot

Hi @vespino
Pls try to update Certman module version.
| certman | 15.0.22 | Enabled | AGPLv3+ |

The system shows no updates.

Pls run below command on your PBX CLI:

fwconsole ma downloadinstall certman --tag 15.0.22

Thanks, I will give that a go.

As has come up in the forum several times over the last month or so, it is no longer sufficient to whitelist only for hosts to allow validation. LE validation can come from anywhere, so you must allow world access to port 80.

This topic was automatically closed 31 days after the last reply. New replies are no longer allowed.