FreePBX 13.10.66 - Self Signed Certificate error - Can't register FreePBX - SOLVED

English isn’t my native language, sorry in advance.

I’m trying to install the FreePBX13.10.66 64 bit version. When I try to register I got the error: " Unable to display activation page. Error returned was: SSL certificate problem: self signed certificate in certificate chain".

I read a lot about this error, tryed everything I found but can’t solve this problem.

I’ve tryed to reinstall pm2 but got this error:

[root@localhost ~]# fwconsole ma downloadinstall pm2
No repos specified, using: [standard,extended] from last GUI settings

Starting pm2 download…
Processing pm2
Verifying local module download…Verified
Extracting…Done
Módulo pm2 baixado com sucesso
/usr/lib/node_modules/npm/bin/npm-cli.js:79
let notifier = require(‘update-notifier’)({pkg})
^^^^^^^^
SyntaxError: Unexpected identifier
at exports.runInThisContext (vm.js:73:16)
at Module._compile (module.js:443:25)
at Object.Module._extensions…js (module.js:478:10)
at Module.load (module.js:355:32)
at Function.Module._load (module.js:310:12)
at Function.Module.runMain (module.js:501:10)
at startup (node.js:129:16)
at node.js:814:3
Node Package Manager is not installed
Unable to install module pm2:

I think it’s something with npm:

[root@localhost ~]# node --version
v0.12.18
[root@localhost ~]# npm --version
/usr/lib/node_modules/npm/bin/npm-cli.js:79
let notifier = require(‘update-notifier’)({pkg})
^^^^^^^^
SyntaxError: Unexpected identifier
at exports.runInThisContext (vm.js:73:16)
at Module._compile (module.js:443:25)
at Object.Module._extensions…js (module.js:478:10)
at Module.load (module.js:355:32)
at Function.Module._load (module.js:310:12)
at Function.Module.runMain (module.js:501:10)
at startup (node.js:129:16)
at node.js:814:3

root@localhost ~]# rpm -qa | grep npm
[root@localhost ~]# yum install npm
Plugins carregados: fastestmirror, kmod
Configurando o processo de instalação
Loading mirror speeds from cached hostfile
Nenhum pacote npm disponível. (no npm package available)
Error: Nada a ser feito (nothing to do)
[root@localhost ~]#

Sorry for the messy post.

It’s my first post, don’t know how to post logs.

Any ideas how to solve this?

You have something that is intercepting communications between FreePBX and the outside world. Speak to your network guys and get them to remove SSL FIltering/Packet Inspectiong.

xrobau, thank you very much for your answer!

Before post this thread I did make a sniffer at the network interface and did see that I have traffic between my server and I think the sangoma server (151.101.0.162). Even with this traffic you think that may be a filtering issue?

In that sniffer I got a Encrypted Alert (error 21).

Although I will contact the network administrator and ask him to take a look.

Best Regards

Nope. Most of our non-CDN stuff is around 199.102.something.something (depending on the service). Sounds like your DNS is wrong. Try setting it to 1.1.1.1 and 8.8.8.8

Here is how you can validate that you’re connecting to the right things. If the output of either of those two commands aren’t exactly the same as the result I pasted here, something is messing with your internet traffic.

[root@sng7 ~]# host katanafpbx.schmoozecom.com
katanafpbx.schmoozecom.com has address 199.102.239.11
[root@sng7 ~]# openssl s_client -connect katanafpbx.schmoozecom.com:443 < /dev/null | openssl x509 -noout -text
depth=3 C = US, O = "The Go Daddy Group, Inc.", OU = Go Daddy Class 2 Certification Authority
verify return:1
depth=2 C = US, ST = Arizona, L = Scottsdale, O = "GoDaddy.com, Inc.", CN = Go Daddy Root Certificate Authority - G2
verify return:1
depth=1 C = US, ST = Arizona, L = Scottsdale, O = "GoDaddy.com, Inc.", OU = http://certs.godaddy.com/repository/, CN = Go Daddy Secure Certificate Authority - G2
verify return:1
depth=0 OU = Domain Control Validated, CN = *.schmoozecom.com
verify return:1
DONE
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 4146748324505689562 (0x398c35a1771b9dda)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2
        Validity
            Not Before: Oct  5 15:14:39 2016 GMT
            Not After : Oct 18 19:36:01 2019 GMT
        Subject: OU=Domain Control Validated, CN=*.schmoozecom.com
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:c4:c5:5e:e0:df:8e:03:a5:4d:70:8e:b9:ca:db:
                    ba:52:85:35:59:7d:fa:9c:71:75:6f:a4:53:e9:39:
                    95:57:22:f6:f9:48:c7:ef:78:4b:70:33:b3:70:9a:
                    63:14:7d:88:a7:b6:96:9f:c4:1b:28:ca:73:ee:6b:
                    6d:c2:70:79:7f:94:3a:23:49:b3:30:1e:43:14:92:
                    4a:66:fb:6c:c2:1b:fa:4a:fe:2e:52:8a:00:cd:b1:
                    f0:c4:f5:aa:a7:eb:ea:22:6e:ed:89:3c:2c:f9:6f:
                    c5:f3:cb:ac:0c:9c:c4:01:81:50:86:2a:4c:01:e3:
                    c2:13:5d:13:6f:c3:e3:63:b9:d1:3f:4f:f9:5d:a8:
                    49:a1:cb:ae:c5:df:28:1f:e4:79:16:18:06:91:0a:
                    05:b2:a4:f6:79:1b:16:94:e0:f4:e0:e5:bc:2e:43:
                    f2:83:88:7f:09:66:66:f8:e7:94:ce:09:2b:8c:6a:
                    55:20:59:f6:93:73:d4:d4:a4:85:2a:89:b9:ed:7c:
                    da:11:e6:74:c0:84:5f:ed:62:86:2d:3c:33:c0:4f:
                    2d:bb:42:25:b1:b6:7a:d1:7f:e5:a9:05:8d:21:c9:
                    26:38:c0:05:9c:84:fe:ec:b7:f9:23:d7:bd:2b:a8:
                    f6:82:95:fc:3b:54:b1:1f:0d:a5:57:af:7b:f0:86:
                    4c:47
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Extended Key Usage:
                TLS Web Server Authentication, TLS Web Client Authentication
            X509v3 Key Usage: critical
                Digital Signature, Key Encipherment
            X509v3 CRL Distribution Points:

                Full Name:
                  URI:http://crl.godaddy.com/gdig2s1-317.crl

            X509v3 Certificate Policies:
                Policy: 2.16.840.1.114413.1.7.23.1
                  CPS: http://certificates.godaddy.com/repository/
                Policy: 2.23.140.1.2.1

            Authority Information Access:
                OCSP - URI:http://ocsp.godaddy.com/
                CA Issuers - URI:http://certificates.godaddy.com/repository/gdig2.crt

            X509v3 Authority Key Identifier:
                keyid:40:C2:BD:27:8E:CC:34:83:30:A2:33:D7:FB:6C:B3:F0:B4:2C:80:CE

            X509v3 Subject Alternative Name:
                DNS:*.schmoozecom.com, DNS:schmoozecom.com
            X509v3 Subject Key Identifier:
                5C:1A:0A:9F:3B:9C:36:10:B8:48:1D:70:77:23:CE:82:E1:1C:FB:A4
    Signature Algorithm: sha256WithRSAEncryption
         51:94:bd:e2:9c:f0:eb:12:93:0b:25:94:81:87:cd:34:2e:d6:
         56:0e:e2:c8:d8:3c:20:d4:f9:cd:83:5c:45:5f:7a:b3:5e:3e:
         22:b4:fe:78:6a:29:71:c0:1d:0d:76:c8:f3:7e:90:ad:aa:e0:
         e5:82:46:37:69:3e:40:c0:85:6f:4c:b9:3e:a0:c6:6b:d5:e8:
         db:c3:55:92:21:77:01:30:81:4e:be:c0:4a:59:18:a0:9d:79:
         a6:89:f8:df:6c:08:17:fe:84:11:3e:20:17:c8:ac:90:90:a2:
         73:2c:04:a2:d2:1c:68:ff:45:fa:e3:b2:02:14:bd:d4:10:77:
         3a:b6:4d:4f:59:ad:e4:a4:0f:2d:1f:81:55:ac:60:83:79:8f:
         1c:b2:58:bd:18:ca:2e:f7:f2:db:c5:85:a4:24:b3:68:4d:f4:
         ad:df:b9:c6:f4:bd:d8:d3:9a:50:5d:31:5c:31:1f:79:48:40:
         9a:ea:37:0a:44:f2:b8:c7:98:13:95:5b:bc:f5:46:a8:d0:15:
         c1:05:2a:b2:bd:23:ef:78:57:2b:4a:95:5c:8d:64:3e:c9:f6:
         c8:88:03:bd:8e:14:ef:d9:70:93:6c:c0:f4:4a:c4:21:c0:07:
         77:87:22:52:c3:76:2c:bf:37:46:b5:d3:b2:01:ef:89:ae:7e:
         1d:9d:cf:15
[root@sng7 ~]#
1 Like

Edited.

Rob, it was a filtering option at the Sonic Wall.

Solved!

Thank you for your help!

This topic was automatically closed 7 days after the last reply. New replies are no longer allowed.