FreePbx shows: Some Certificates are expiring or have expired

freepbx
v7

(Alex Ivashenkov) #1

NethServer Version: 7.4.1708
Module: FreePBX
FreePBX dashboard shows following messages:
“Security Issue
Some Certificates are expiring or have expired
This is a critical issue and should be resolved urgently”

In details: “There were no files left for certificate “default” so it was removed”

When I click “Resolve”, I see one self-signed certificate which will expire in year 2027 and marked as default.

Everything continues to work. On Nethserver admin panel Lets encrypt certificate activated and everywhere I see green lock (when I try to connect to server with https)

Any ideas?


(Markus Neuberger) #2

I found this, question is open since Oct 16:


(Alex Ivashenkov) #3

I saw it already. Won’t help


(Markus Neuberger) #4

I saw you posted in freepbx forum, I hope they give an answer. I am actually installing FreePBX on a testserver. I’ll try to reproduce the certificate issue.


(Markus Neuberger) #5

Sorry, I couldn’t reproduce this issue.
I tried change/add/remove certificate in NethServer and in FreePBX, moved certs away from /etc/asterisk/keys/integration and changed system times but no luck.

After removing the certificate in freepbx HTTPS still works.

Is the message still in dashboard? If everything works, I’d just ignore and click it away.

You may also try removing the certificate in FreePBX certificate manager, create a new one, make it default and check if something changes in dashboard between the steps.

So I think if you do not use WebRTC or SRTP you can safely ignore the warnings. There’s also a mini http server with freepbx (in advanced settings) but it’s disabled by default, maybe the certs are used there.


(Alex Ivashenkov) #6

I tried to remove all certificates in FreePBX including default, and generated new self signed certificate. I hoped it will fix the problem. Nothing changed. Same error. Generation lets encrypt certificate from freepbx makes an error.


(Giacomo Sanchietti) #7

@mrchiao @Stll0 did you experience such issue?


(Stefano Fancello) #8

You are right, FreePBX certificate are just for SRTP or WSS

Looking at certman module code /var/www/html/freepbx/admin/modules/certman/Certman.class.php I see that this message error is triggered if there are a certificate saved in certman asterisk table but there aren’t certificate files. Because of that, you should have solved removing and recreating certificate.
Try this:

  • remove default certificate
  • make sure that there’s no more this certificate in certman mysql table
    mysql asterisk -e 'select * from certman_certs where basename = "default"'
  • look if there are still files for this certificate in /etc/asterisk/keys/
    ll /etc/asterisk/keys/default*
  • remove notification from FreePBX dashboard by clicking on :negative_squared_cross_mark: icon

let me know if warning comes again or if you find something strange trying the above


(Alex Ivashenkov) #9

Thank you for all your effort. You are trying to help so many people… I really appreciate it. I bet, we have better and more enthusiastic support team then FreePBX community has. It was test virtual server where I tested what I can do and what I can’t. I haven’t expected that someone will find a solution (especially after month of silence on FreePBX forum). So I just killed the server and started over. Next time I will probably return to this topic. But right now everything is working as designed.
Thanks again


(Alessio Fattorini) #10

ooooooh yes! :heart_decoration: Thanks to @Stll0 @mrmarkuz and many others