Plantronics + Polycom. Now together as Poly Logo

Trio8800 connection with Visual+ fails when mr.pair.tls.enabled=1

Advisor

Trio8800 connection with Visual+ fails when mr.pair.tls.enabled=1

Phone Information
Phone Model Trio 8800
Part Number 3111-65290-001 Rev:B
MAC Address 64:16:7F:B9:AC:DE
Wi-Fi MAC Address 64:16:7F:B9:AC:DF
Bluetooth MAC Address 64:16:7F:B9:AC:E0
IP Mode IPv4
   
UC Software Version 5.9.5.2982
Updater Signature Release

 

 

Pairing a Visual+ to a Trio8800 fails when mr.pair.tls.enabled=1 with mr.pair.tls.enabled=0 the units pair as expected.

 

The log on the Trio800 shows the failure

1201133105|mr   |4|00|mrMainPairResponse: Connection with 0004f2ffec4e failed
1201133205|mr   |4|00|mrMainPairResponse: Connection with 0004f2ffec4e failed
1201133305|mr   |4|00|mrMainPairResponse: Connection with 0004f2ffec4e failed

 

As does the log on the Visual+

 

1201183858|mrcon|4|00|mrConnCbHttp-CertValidate: Invalid cert error 18 for /CN=64167FB9ACDE
1201183958|mrcon|4|00|mrConnCbHttp-CertValidate: Invalid cert error 18 for /CN=64167FB9ACDE
1201184058|mrcon|4|00|mrConnCbHttp-CertValidate: Invalid cert error 18 for /CN=64167FB9ACDE

 

The certificate on the Trio8800 is a bit odd, it appears to be self signed / issued with a valid from of 1/1/1970 to 12/27/1989. Looking at other deployed Trio8800 in the environment they appear to have certificates issued from the  'Polycom Equipment Issuing CA 2'

 

I've attached the factory certificate from the problem Trio8800 below.

 

-----BEGIN CERTIFICATE-----
MIIDKTCCAhGgAwIBAgIJAKNGkqB4Ch8/MA0GCSqGSIb3DQEBCwUAMBcxFTATBgNV
BAMTDDY0MTY3RkI5QUNERTAeFw03MDAxMDIwMDAwMDBaFw04OTEyMjgwMDAwMDBa
MBcxFTATBgNVBAMTDDY0MTY3RkI5QUNERTCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBALABXMQh2mxn9pomdmEfuykPjQTdK9hpUJkWtpuE/RBAIGVFJF2b
yy0DxiZyrBzUrtgN1ycTqjw9uvTVKbXzwh1LhiHEbHZ048caYOe4Qfyjhx0PGbwb
WayZz9QZlGe5qd3P3OiwV63gum7roS+rlWr/FOpC7T4AZRNCzDN6KaQmlPsuW+jx
hUaZYECLC0fyREkkSrNrV3pSsbe2++mR4HbwlfXM2nmCMpd8KDjwJlkZFYwWCgUD
mnaLGkyg2bkefTNx5u12G0Uc60hxqa2PtNuu68mEXcx6r/wh+9Tvp9FmBILPWclj
PiNyqYdn+wH5DNZm+2IUyXL+Gi74pfmFvP8CAwEAAaN4MHYwHQYDVR0OBBYEFNZO
+waTBUp4lCCZ8KhxMI2lPTRyMEcGA1UdIwRAMD6AFNZO+waTBUp4lCCZ8KhxMI2l
PTRyoRukGTAXMRUwEwYDVQQDEww2NDE2N0ZCOUFDREWCCQCjRpKgeAofPzAMBgNV
HRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQCEKYOnkREXgsioCQ6dSolT4QVc
1o9A4u531SnSqx8W5QU8Js+JwoTNAbshgzgVUxCGzJcoDKKGe9ADM+wADaDzQgNI
O0FzNjuVVauJ6Bkm4elU1rLjLsCOxRq4gvuv5zUteUyWUyK1SIXQiqWVO1ZYVXx+
c0TxVrOCb56pgRQxD4DUlKc67S54WaxubqFutQtpv+jXwPiM2fkEN3FQ5QQQnlnL
ziuvHZvDArB59g5aui1vMSBZmFLYFZ7qrfsrNk9zdKMVKkre7WVrxi8rzc3drLc6
6f9LT8xfBjYDvluaVy0hmYQC4xZQwADieOMFTKt9KKh4ImhxM27sszJwdDl5
-----END CERTIFICATE-----
Message 1 of 4
3 REPLIES 3
Polycom Employee & Community Manager

Re: Trio8800 connection with Visual+ fails when mr.pair.tls.enabled=1

Hello @JamesW ,

Welcome back to the Poly community.

Some or a couple of your old post(s) or reply(s) to them => here <= are still open/pending as you have not marked these as "Accept as a solution" or at least provide some form of feedback or answer.

If they are in this state nobody finding them via a community search will know if an answer or advice provided was useful and has maybe helped you.

Could you therefore kindly go over them and mark or answer as appropriate?

If they are marked as "Accept as a solution" other users can find these easier and it helps them to utilise the community more efficiently. Please do not simply mark them without any type of feedback.

 

As you have not provided any details if this new issue is a day 1 issue or else we cannot really commend.

 

I may have a look tomorrow at the serial provided but I assume you know the drill on how to get official support if this unit is still in warranty.


Please ensure to provide some feedback if this reply has helped you so other users can profit from your experience.

Best Regards

Steffen Baier

----------------
The title Polycom Employee & Community Manager is a community setting and does not reflect my role. I am just a simple volunteer in the community like everybody else. My official "day" Job is 3rd Level support at Poly but I am unable to provide official support via the community.

----------------

Notice: This community forum is not an official Poly support resource, thus responses from Poly employees, partners, and customers alike are best-effort in attempts to share learned knowledge. If you need immediate and/or official assistance please open a service ticket through your proper support channels.
Please also ensure you always check the VoIP , Video Endpoint , Skype for Business , PSTN or RPM FAQ's
Message 2 of 4
Advisor

Re: Trio8800 connection with Visual+ fails when mr.pair.tls.enabled=1

This Visual+ has worked elsewhere in the environment previously.

 

This Trio had not previously been deployed with a Visual+.

 

The difference in the factory device certificate combined with the behaviour suggests the Visual+ is not trusting the factory device certificate presented by the Trio8800, i think the warranty on 64167FB9ACDE only ran through 2020-10-22.

Message 3 of 4
Polycom Employee & Community Manager

Re: Trio8800 connection with Visual+ fails when mr.pair.tls.enabled=1

Hello @JamesW 

 

our records show this sold via Scansource back in 9/23/2019 but there should be a grace period especially as this would require an RMA as the Trio should have a factory-installed Certificate.

 

Best regards

 

Steffen Baier

----------------
The title Polycom Employee & Community Manager is a community setting and does not reflect my role. I am just a simple volunteer in the community like everybody else. My official "day" Job is 3rd Level support at Poly but I am unable to provide official support via the community.

----------------

Notice: This community forum is not an official Poly support resource, thus responses from Poly employees, partners, and customers alike are best-effort in attempts to share learned knowledge. If you need immediate and/or official assistance please open a service ticket through your proper support channels.
Please also ensure you always check the VoIP , Video Endpoint , Skype for Business , PSTN or RPM FAQ's
Message 4 of 4