07 Let's Encrypt Installation - FreePBX 101 v15

preview_player
Показать описание
New for 2021! FreePBX 101 v15 is a comprehensive tutorial series that covers everything you need to know to plan for, install, and configure the open source FreePBX phone system from Sangoma.

In this video, we will go over how to install a Let's Encrypt certificate in FreePBX for secure HTTPS communication.

Timecodes:

00:00 Intro
00:40 Why do we need a Let's Encrypt cert?
01:40 Enable Let's Encrypt
03:24 Let's Encrypt firewall settings
05:02 Generate Let's Encrypt certificate
06:17 Install Let's Encrypt certificate into FreePBX

----------------------------

Follow me on Twitter: @crosstalksol

Connect with Chris:
Twitter: @CrosstalkSol
Рекомендации по теме
Комментарии
Автор

Chris your are literally the best in the business

dougnelson
Автор

Wow! This is the best Letsencrypt automation I've seen around. Thanks for the video.

benbabajide
Автор

2 problems solved!!!
1st) If port management page looks funny and you cannot save just clear your browsers cache and reload.

2nd) I didn't have to change anything to port management to install LetsEncrypt. I followed the video no problem, but an extra step is required (if it's not automatically done). After you install the certificate head back to port management and select your FQDN under the green bar HTTPS Address.

angelosnegkas
Автор

This was extremely helpful. I appreciate all of your guides. Very informative

bradjennings
Автор

Let's Encrypt works differently in V16 and I haven't been able to get it to work

Ozyank
Автор

ok, so what is that new certificate used for? communication from my computer to my local PBX? or from my local PBX to the trunking service somewhere in the cloud? maybe both?

mrxmry
Автор

Hey guys for on prem installations I spent the whole day trying to figure out why when logging using my FQDN I would get a time out after the login screen. Im not sure if its router specific but apparently mine doesnt like hairpin traffic. So i have to use my local ip when on the same network but if accessed from outside my network it all works perfectly. Make sure to forward yours ports on the router. as well.

aldotech
Автор

Chris, please make a tutorial on how to configure webrtc phone ucp

_vegapunk
Автор

Chris, I tried contacting you for some consultation work on your site. I got a response back from someone saying “Thanks for reaching out! Unfortunately though, we are completely overbooked and are not taking on new clients at the moment.”
I was looking for help setting up a Vega 60gv2.

louisstargel
Автор

Great Config, Cloud you do a Video for implementation without VPN (freePBX open port to internet)

giancarlosrm
Автор

I know you done some video's about Sangoma's SBC. My question is does Sangoma's SBC also have let's encrypt pre installed with automatic renewal, As freepbx has

hakanwall
Автор

I'm wondering whether changing the Admin port and setting LE port to 80 is necessary in FreePBX 16, or if there is some extra/magic sauce that makes doing so no longer relevant...? On a clean FreePBX 16 install, with firewall enabled, sole eth0 port in Internet zone, responsive firewall enabled, and DNS/FQDN/hostname set, I requested an LE cert and received a response with certificate very quickly. I hadn't made any changes to port assignments. After installing the LE cert for Apache, I then enabled a number of the https services on their default ports (including admin on 443) and forced https. I'm a little concerned that if I don't change the Admin http port (e.g. to 8080) and explicitly set LE http to 80, auto renewals will fail...?

cloudbase
Автор

There was a time when Let's Encrypt didn't auto renew and you had to create a cron job that ran I believe every month to renew. If you missed that window the cert expired and hair would be pulled out.

SkittleKicksPlays
Автор

My screen for port management is different than yours. I have below insecure Port (http), Port 8080 and below that is Enter custom port. Then to the right is Force with an arrow. Then Secure Port (https) HTTP Not available, below that Enter custom port. When I make the changes you suggested and select update Now, ann the Enter custom port boxes go red. Firewall is not updating.

jamessinger
Автор

Hello Chris,
I keep getting an error when trying to generate the certificate ( Unable to update challenge :: authorization must be pending ) any idea what's the issue here? Or anyone else got the same issue? This is on the latest version of FreePBX

donnycruz
Автор

is that a white raspberry pi behind you ?! so pretty

danielgx
Автор

How to handle if XML files won’t pass after turning on let’s encript?
Port for RestAps needs to be defaulted to https?

jamespeister
Автор

Hostname / FQDN error!
"Domain name does not end with a valid public suffix (TLD)"
don't know how it works, maybe a video. nice work

rjdp
Автор

I wish they supported dns challenge since it's not reasonable to dedicate a port just for that.

ikkuranus
Автор

Does this need to be done if you're using it before a firewall on a LAN? Any benefit other than the admin website being encrypted? Seems like a lot to register a public IP to a DNS record just for this.

garrymca