AudioCodes Mediant VE: automated wildcard SSL certificate renewal with Let's Encrypt
Certificate automation on legacy SBCsMANUAL FIX INSIDEFREE — NO SIGNUP
Quick answer. The Mediant VE accepts certificates via its REST API as well as the Web GUI, and the manual GUI path is the only reason renewal is a human chore. A wildcard certificate issued via the DNS-01 challenge covers every tenant domain, and the renewal can be pushed with the same REST upload on each cycle — turning the 90-day trap into a scheduled job that runs in seconds. The setup is one ACME client, one DNS credential, and one upload script; after that, renewals are invisible.
The raw code check
Run this before you change anything — it confirms the root cause in one pass:
GUI renewal (human-driven)FAIL
day 90: download fullchain + key from CA portal
Web GUI → Security → Certificates → upload ×1 per device
restart SIP TLS interface during business hours (or don't sleep)
repeat per tenant — miss one, office goes dark
REST renewal (scheduled)OK
cron: acme.sh --issue --dns dns_<provider> -d '*.sip.example.com'
upload: POST fullchain to Mediant REST cert endpoint
reload: SIP TLS listener picks up chain — no call drop
next renewal: day 60, automatic — nobody involved
The manual fix — 3 steps
- Issue a wildcard certificate with the DNS-01 challenge. Run an ACME client (acme.sh or certbot with your DNS provider's plugin) on any Linux host that can reach your DNS provider's API. A DNS-01-issued wildcard for *.sip.example.com covers every tenant subdomain with one certificate, so you renew once, not per tenant.
- Upload the renewed chain via the Mediant REST API. Instead of the GUI, POST the fullchain (and key, as your policy requires) to the Mediant's certificate import REST endpoint with your admin credentials, then trigger the TLS listener reload through the same API. The Let's Encrypt Auto-Formatter here produces the exact bundle layout the import expects.
- Schedule it and force one test cycle. Wrap issue → format → upload → reload in a small script and let the ACME client's renewal cron call it. Force one renewal now (acme.sh --force --renew) and confirm from the device: the certificate on the SIP TLS interface should show the new serial and a ~90-day horizon, with zero dropped calls during the reload.
The automated alternative
If you'd rather never do this again: VoipFlow runs this whole class of maintenance as software — certificate issue-and-bind in about 12 seconds, signaling on port 5062 so SIP ALG rewriting never engages, per-tenant isolation, flat $399/mo. The 14-day sandbox is free, no credit card, and no sales follow-up unless you ask for one.
Deploy Free 14-Day Sandbox — No Credit Card Required