Improved Security Final to be merged into Update 8

Update 7A is now ready for installation - but because these security changes require careful preparation and further understanding, we’ve decided to merge the final release into Update 8. On a positive note, this gives your admin more time to prepare and implement the security changes effectively.

Not to disappoint those who want to go ahead and install the security updates right away, you can still do so with this Beta version - implemented to avoid auto install on systems with auto update enabled. Keep reading to refresh your memory on what’s included so far, recent fixes and the status of the Desktop App.

7-step Action Plan 'EFTA' in Full Swing

BLF in the 3CX Web Client

You’ll recall in Update 7A Alpha, we initiated the first phase of our 7-step action plan ‘EFTA’. Our primary focus is enhancing our product security. Here’s the recap of what we’ve included:

  • Implemented password hashing.
  • Eliminated password and config file from Welcome Email.
  • Restricted access to the Web Client admin interface by IP.
  • As a supporting product feature, we also added the BLF view in the dialer of the Web Client and PWA to address the concerns of those who cited it as a key reason for not using it.

What We’ve Fixed Since Update 7A - Alpha

  • Resolved issue where PWA Install modal dialog does not appear after the first login.
  • Fixed problem where recent Safari updates prevent Web Client from opening.
  • Addressed an issue with SetupConfig where "Set your password" is shown in the last step of the installation wizard.
  • Added an "OK" button to the ‘’forgot password’’ form to return to the Management Console login page.
  • Improved functionality for resetting forgotten root credentials for the Management Console: This can now be reset by entering System Owner’s email address.
  • Improved dialer functionality for Web Client and PWA due to BLF addition: Focus is maintained even when Web Client or PWA is closed.
  • Added the configuration file to provision Android and iOS Mobile Apps: When users login to the Web Client on a mobile device, they can now download the config file from the Apps page.

Desktop App Remains Unchanged

The Desktop App remains unchanged from Update 7. Quite simply as a result of recent events, we’ve chosen to remain with the current - security tested - version of the Desktop App. We’re sure you’ll appreciate our caution! This decision brings with it a number of minor issues as follows:

  • Changing the password of the extension's Web Client access results in the Desktop App being unable to reconnect. A manual restart of the Desktop App is required in order to access the Admin View or Settings.
  • The Apps Page won’t display new options and won't allow downloading of the configuration file required to run the legacy Windows App.
  • If the Management Console restriction is enabled for the Admin View, Admin Options will still remain visible. However, no action can be taken from a restricted IP address.

How to Get Update 7A - BETA

Users can access the update from the Updates section in the Management Console if you’re on Update 7.

View the complete changelog here.

Stay Informed

Hit the follow button on Twitter and LinkedIn for blog updates on the Update 8 release up next.