Baikal: Error syncing carddav with AVM Fritzbox

Created on 5 Jul 2020  路  25Comments  路  Source: sabre-io/Baikal

baikal version 0.7.1, FritzOS 7.19 (labor)
Fritzbox ist a home router by the german manufacturer avm. With its new beta ("labor") os, it is possible to sync addressbooks for connected telefones with a carddav server. It is reported, that it works with carddav in nextcloud. Trying to sync with baikal i get an "error 26". Unfortunetly there is no really bugtracker at AVM/Fritzbox, so perhaps here is someone with an up an running config for this special situation or the same error. My Baikal is up and running well for years, but it is on a webspace given by a german provider without a shell, so debugging on the host side wont be possible.

Most helpful comment

Got answer by avm: It ist the digest Authentication! With basic authentication the it should work. They want to add digest auth in next version. I hope switching to basic auth won't lock out me from baikal...
I'll close this in a few days...

All 25 comments

The same here with the final 7.20 at the 7590.
After the error code 20 was already fixed in the laboratory firmware, I opened a support ticket at AVM. I'm curious for what error code 26 is. As soon as I get an answer I would post it here.

short info: I got an answer, should create a support file during the error and send it to avm. unfortunately i can't at the moment - please open a ticket and create and send the file to AVM. I try to do this as soon as possible - the more you report the error, the better it is. As far as error 26 is concerned, I have no answer.

@nillebor: Thank you so far. But i went back to original os and because my router is a 7530 i'm not already at 7.20. As soon as i get official os 7.20, i'll try to follow the way you described. My problem with "laboratory" was, that one only can leave comments, but cannot open a really inicident. In the answer of AVM you got a guide to create the support file? We'll see...

@oerly:

create support file
you can open a ticket at avm here. just choose telephony+fax> phone book from the bottom you will find "to the support form"

For me it works:
Fritz!Box 7590 - FRITZ!OS: 07.20 - Baikal 0.7.1

You have to chose:
Provider: CardDAV
CardDAV-Server: https://IP-to-baikal/card.php/addressbooks/username/default/
(If I only use https://IP-to-baikal/, then I get an error! Https is mantatory btw!)
Username: username
Password: password
Thats it!

The strange thing is, that the Fritz!Box only uses the first addressbook of the user in alphabetic order, what ever you write in the URL above! So if the user has 2 addressbooks with token "default" and "archive", then the Fritz!Box choses the archive-addressbook.
The Fritz!Box does not adopt photos and you can't add photos in this addressbook in the Fritz!Box.

I can not confirm does not work for me there is always an error message. the fritzbox creates an empty calendar when synchronizing manually because it comes back with an error message. test on a 7590

https://IP-to-baikal/baikal/html/dav.php/addressbooks/username/default
https://IP-to-baikal/baikal/html/card.php/addressbooks/username/default
https://IP-to-baikal/baikal/html/dav.php/principals/username/default
https://IP-to-baikal/baikal/html/card.php/principals/username/default

is somehow typical avm - take a long time and then it still does not work. avm know no error description of "error 26"

As I wrote above, here it works with Fritz!Box 7590 and the official OS 7.20, but only in the way I explained.

How is the configuration of your Baikal-Server?
I'm a little bit confused about the content of your URLs which you published here.

What happened, if you type:
https://IP-to-baikal/baikal/html/dav.php/addressbooks/username/default
in a normal webbrowser (of course with correct data)?

Error 26 I only got, when I entered the wrong URL in the Fritz!Box.

@gruenie Do you use an internal or external IP address for your Baikal installation?
With an internal IP address I always get error 26. Using the same path in my web browser the address book is shown. As there is no SSL certificate for the internal IP address this might cause the problems.

I'm using an external IP-address for the baikal-server.
It's secured by an regular domain validated certificate.
It may be, that the missing ssl-certificate causes the problem.
If your read the inforamtions in the Fritz!Box carefully, they say there, that an https-connection is mandatory.
And a working https-installation needs a valid ssl-certificate.

But it is easy and not very expensive to buy a domain-validated ssl-certificate and to install it in an internal nas for example.

My Baikal installation is on a Raspi behind a Wireguard VPN. So I don not need to care about securing the web server.
I read the point with SSL secured connection but this does not really make sense when using an internal IP behind a VPN.

I understand what you mean, but then it probably will not work at the moment - until AVM may change it. But probably they wont, because normally today it's a basic to use ssl-connections.
Where is the problem to buy the cheapest domain-validated ssl-certificate? It just costs a few Euro. Or mayby lets encrypt could work.

I already use a lets encrypt certificate for accessing the Wireguard VPN. That would be no problem. But I do not want to care about a web server exposed to the outside.
It is clear that without changes by AVM there will be probably no solution for this ticket. If I find some time I will open a ticket to remove the SSL enforcement for internal IPs.

To be honest, I don't understand you.
In the time where we discuss here about nothing and which you would need to battle with AVM, you easily had installed the certificate on your internal webserver and all would be probably fine.

I can't imagine that AVM would cancel the requirement for the SSL-connection because it could be a big risk for external connections.
Why they should do that if it is so easy to use a certificate.

And by the way:
For me the internal baikal-server would be not really practicable, because I sync all my calendars and contacts with mobile devices and laptops (Thunderbird) with the baikal-server. It would be a nightmare to always open a vpn-connection from every device to my local natwork to sync the data.
And it could be a security-risk, even if the probability is not very high.

But nevertheless: much luck! :-)

Error 26 shouldn't have to do with SSL, because my Baikal runs on an Httpd with correct certificate. And yes, fritz expects an official certificate. So please don't go off topic by discussing those constellations. And my URL should be correct because it works with different clients. Hope getting 7.20 for my 7530 soon...

thank you all. of course I also have to have an internal address. i use it like oerly. our system is almost 1:1.

It's a shame that AVM has packed it up again, shouldn't any pictures be synchronized? @grueni can you confirm that? where should the advantage be? You can argue about the system whether sync over the web browser or vpn - but I think the last one is better. That would be as if avm dyndns would abolish and only use myfritz or if the internal ip is the same for everyone just because it is enough.

I thank you but that you have all brought light into the dark. I'll ask AVM about it and trigger the tick. @oerli, please also open one;)

Looks like this is solved, right? The cause for the problems seems to be that AVM forces everyone to use a SSL certificate for the web server. Therefore, this is not a problem that can be solved by Baikal.

@gruenie Thank you very much for finding the cause for this issue!

@ByteHamster : please read the full thread even it is long. As reported, error 26 results at hosts that are equipped with an official SSL certificate like at my one too. Today I got 7.20 for my 7230 and because the error resists, I opened a ticket at avm. I offered them to try on my Baikal. I'll report than...

@nillebor:
As I already wrote: Photos of contacts are not being synchronized and it is also not possible to add them manually to this "net-accressbook" in the FRITZ!Box.
But nevertheless it's a nice new feature of the FRITZ!Box to be able to use the baikal-addressbook at home too.
If it is important to you to add photos, then you need to use an intern phonebook of the FRITZ!Box. You can create several phonebooks in the Fritz!Box (intern and extern), but you only can mount one of them to one FRITZ!Fon (but you can change them in the phone).

@oerly:
What do you mean with going offtopic???
I explained, that it works for me with a FRITZ!Box 7590 with OS 7.20, but only if I use the URL like exactly decribed.
You have a FRITZ!Box 7530 and did not have the latest OS 7.20 when you wrote this post.
Now you have the new OS but you did not tell us if it wors now.

Short interim message: avm is in deep analysis and today they accepted my offer for an account. Stay tuned...

Got answer by avm: It ist the digest Authentication! With basic authentication the it should work. They want to add digest auth in next version. I hope switching to basic auth won't lock out me from baikal...
I'll close this in a few days...

Yes, it works. Basic auth shouldn't be a security lack, because TLS is mandatory. Since i have no FritzFon yet, i can't try out, if images are synchronized. So you may have your own issue with avm. This is solved.

can you explain to me what you have changed now? currently do not fully understand.
is it safe with the pictures or don't you know? maybe someone else can say something about it. does the syncronization of the images from google and co?

The option is useless for me without pictures, because the phone book can also be imported and saved quickly by hand. if avm wants to install something you have to wait a long time, let's see if that happens this year. the current firmware was announced for the end of 2019

As I wrote,I can't check it out with the images. The authentication method is to change in Baikal after logging in as admin.

Am 8. August 2020 17:15:16 MESZ schrieb nillebor notifications@github.com:

can you explain to me what you have changed now? currently do not fully
understand.
is it safe with the pictures or don't you know? maybe someone else can
say something about it. does the syncronization of the images from
google and co?

The option is useless for me without pictures, because the phone book
can also be imported and saved quickly by hand. if avm wants to install
something you have to wait a long time, let's see if that happens this
year. the current firmware was announced for the end of 2019

--
You are receiving this because you modified the open/close state.
Reply to this email directly or view it on GitHub:
https://github.com/sabre-io/Baikal/issues/949#issuecomment-670940330

--
Besten Gru脽
Michael Prinz

Yeah you are right

after changing the potion the synchronization works without problems. Images are not transferred, you can tell by the small icon in front of the name, which is not there. as soon as a picture is deposited, the logo is visible.

thanks for the tip, i hadn't understood that correctly before

The latest update to Fritz!OS 7.25 also supports Digest as authentication method, so error 26 shouldn't occur anymore. Its changelog is not exactly talkative, only stating that some CardDAV integrations failing with error code 26 has been fixed.

After a very short test, images are still not synchronised.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

sicherist picture sicherist  路  4Comments

Superwallah picture Superwallah  路  8Comments

gitfvb picture gitfvb  路  4Comments

FelixR2002 picture FelixR2002  路  7Comments

lunixyacht picture lunixyacht  路  8Comments