2021-10-05 Yealink Provisioning Errors (Resolved)
Table of Contents
Event Description: Yealink devices under version 96.86.0.37 were unable to pull configuration files from the NDP server.
Event Start Time: 2021-10-05
Event End Time: 2021-10-06
RFO Issue Date: 2021-10-06
Affected Services
Yealink devices under version 96.86.0.37 were unable to pull configuration files from the NDP server.
Root Cause Analysis
On 9/30/2021, Let's Encrypt expired the intermediary X3 certificate used for their SSL certificates. In preparation for this, we had already issued new certificates using the updated X1 intermediary certificate as of June 2021. However, this did not remove the X3 intermediary certificate.
Yealink devices with firmware below 96.86.0.37 required that all intermediary certificates be valid in order to download configuration files. All other devices ignored the expired certificate as long as there was a valid certificate in the chain.
We removed the Let's Encrypt certificates and installed traditional SSL certificates on NDP. Yealink also provided updated firmware 96.86.0.37 and 96.86.0.38 which addressed this issue. Both have been uploaded to NDP.
Future Preventative Action
Should Let's Encrypt, or any other provider chooses to remove an intermediary certificate in the future, we will remove said cert to avoid any conflicts.