15.5 SP5 -> SP6, PINs changed, lost self Identification, lost personalized greetin

Status
Not open for further replies.

Stephen Hellriegel

Silver Partner
Basic Certified
Joined
Jan 1, 2018
Messages
21
Reaction score
6
I have 4 active, many extension, PBX systems. After applying the SP6 update, all 4 systems had the following happen:
voicemail PIN numbers changed for all users
Self Identification messages gone for all users
Personalized greeting gone for all users

After applying the SP6 update, I had the red triangle of distrust due to short passwords. Why two sets of random six digit strings was considered insecure is irrational. It would be better if 3CX implemented weak password checks rather than simple length counts. Anyhoo, per the community recommendation, I hit select all, regenerate, and the red triangles went away. Happy day, so I thought.

I am wondering if by selecting regenerate I reset the PINs, cleared the self identification message, and wiped personalized greetings?

I have about 200 people who are wondering what to do now. I know I need to tell them to re-record, but I want to know how to avoid this in the future. Anyone else experience this?

-Steve
 
I have not regenerated any of mine yet and all the pins and greetings are still there and functioning. I will regenerate 1 ext and see what happens and then get back.
 
so i regenerated mine and it did change the pin but my self id and greeting stayed.
 
Thanks!
I understood and expected the user/password for phone authentication to change.
I did not expect the voicemail PIN to change.

I dug a little more into it, and on my PBX instances, I appear to have an issue with the greetings.xml that is in each extension. I tried the Mario trick of select all, edit, OK. This caused the PBX to add an empty "greetings.xml" to all extensions, but it didn't populate the personalized greeting.
<?xml version="1.0" encoding="utf-8" standalone="yes"?>

(Note the first 3 characters are hex 0xBB 0xEF 0x3C)

So perhaps my issue is actually 2 separate issues.
1) Hitting regenerate regenerates the phone access username/password (making them more characters long)
2) I have some other problem TBD in which self_id_prompt.wav and savevmgreeting.wav are not getting loaded into greetings.xml


On one PBX, out of 35 extensions, only one has a non "null" greetings.xml.
<overrides>
<greeting profile="default" file="savevmgreeting.wav" />
</overrides>
 
I should mention I am using the .iso debian image from 3CX, and applying all updates to get the instance up to date. two of these PBX systems are less than three weeks old, one is a two months old, and another is about nine months old. The nine month PBX didn't change PINs or have incorrect greetings.xml.
 
Regenerate pin does not affect the greeting messages.
these things you mention like:
  1. voicemail PIN numbers changed for all users
  2. Self Identification messages gone for all users
  3. Personalized greeting gone for all users

... cannot occur after an update.
These things can occur of you restored a backup without prompts inside.

Yes 6 length passwords are crackable in hours. That's why they are considered weak.

Contact support so they can help you find out why you have those missing greetings.
 
Like I said, 2 separate issues. When an admin hits edit, select all, regenerate, to get rid of the new red triangles that came in 15.5 SP6 we also scramble web access passwords and voicemail PIN numbers. This is is pretty disruptive for the end user base, It would have been much better to have new installs meet the new requirements. For existing installs a parameter we could set to grandfather installations. Everyone has to get new welcome emails and re-memorize their PIN and web passwords.

On the other issue, the greetings.xml in each extension directory is not properly getting generated. I am going to do some linux script action to generate my greetings.xml, restart services and see if we now have personalized recordings. This errant behavior was "new out of the box" with the 15.5SP5 debian 9 ISO image I pulled on August 2 from 3CX and built 4 VMware based PBX. I will update the thread with the results.

I didn't do any backup/restore action, so that certainly has no bearing on the issue. These are freshly built PBX, some of which I rebuilt more than once as I made other infrastructure changes, and completely deleted the VMs between builds. Not my first rodeo generating a PBX image from the ISO.

Add "weak password detection" so you alert us for passwords like "bicycle" or "PrettyPony" or "L0ngPassw0rd".

On the extension "regenerate" button, don't touch PIN or web authentication passwords. Maybe add a "full regenerate" button which scrambles PIN and web auth as well as everything else. Since admins can't see the web authentication password, only our users know them; we can't help them other than re-send welcome emails. Having just done that today, I can tell you this leads to confusion. I had multiple folks at multiple companies tell me they ignored the new welcome email because they had the old email posted on the wall ... by ... their ... phone.
 
Exactly!
To eliminate the new red triangles in 15.5SP6, we have to regenerate everything to meet the new 3CX requirements.

Why scramble the same length PIN number for Voicemails or change the webauth password for folks' web access? Just not a fully thought out process by 3CX! They wanted the perceived improved security of longer passwords, so they pushed it out before implementing automation to help us admins deal with it.

The recommended solution for updating machine authentication (SIP credentials/phone web admin password) is to "select all" and hit "regenerate".
It seems the recommended solution needs to be amended with:
  1. Send email to all users notifying them there will be a new welcome email from 3CX system with new PIN/web passwords.
  2. Select all and send the new welcome emails.
  3. Follow up with email to users stating they should have received their new welcome email, if not, check their spam/junk mail, if still not, contact the admin.

I have one site with 24 extensions which still has red rectangles of shame on the extensions page. I have folks using the 3CX client on their phones, as well as their desk sets. Hopefully this one will go smoother now that I know the drill.
 
Hi Stephen,

Thank you for your feedback. But you can do 1 and 2 with just a few clicks right after you regenerate the passwords? Literally takes a few seconds. As for 3 - if the welcome email went to spam then so would the follow up mail. Thats up to a poor spam filter....

That said an option to not regenerate the PIN is certainly an interesting one. That said poor passwords and PINs are the number one reason a PBX gets hacked.
 
I too followed the advice given in the portal to use "Regenerate" in order to correct the password warning triangles in the list of user extensions. I also have lots of users from all the PBX's I manage calling me and complaining they cannot access voicemail or the webclient.

From what I read, "Regenerate" results in all passwords being reset - the web client, phone management, extension, and voicemail. I think the intent is to reset all when a person leaves an organization and a new user will begin using that extension at some point.

Maybe there should be a different suggestion for how to correct the weak passwords.

-Eric
 
Galea, Nick. *
Many administrators do not have access to mail services of the users PBX system. If we had an extensions option to "select all", and "compose note", which would let us send a short text note (html markup would be a bonus) to all users via the 3CX system, your observation would be accurate. In my specific case, I tasked a client's administrative assistant to setup a 3CX users mail list on their office365 system. I had her add my external email as an allowed sender. This is fraught with error of course; it is a manually maintained and doesn't utilize the 3CX system database. Of course, any mass 3CX email needs to send blind copy or individual emails to protect privacy of users and avoid getting spam filtered. This thread is a caution for other admins who want to get rid of the red triangles (regenerate changes the world and scrambles every users access to their 3CX system). If you want to reduce hacks due to password breaches, use password metrics and refuse to accept a lame password like "B1cycl3s" which meets the 8 digit length rule but would be very early in a dictionary attack.

* That was a hint that many admins need dial by first or last name for the directory. Your insistence of last name only does not accommodate western culture where most folks are known by first name and business only. (Steve at Helldyne, Joe at Boeing, Pete at Cray).
 
Regenerate pin does not affect the greeting messages.
these things you mention like:
  1. voicemail PIN numbers changed for all users
  2. Self Identification messages gone for all users
  3. Personalized greeting gone for all users

... cannot occur after an update.
These things can occur of you restored a backup without prompts inside.

Yes 6 length passwords are crackable in hours. That's why they are considered weak.

Contact support so they can help you find out why you have those missing greetings.


I can confirm that I was able to fix my problem with extensions where users had recorded a personalized greeting but it wasn't playing.

On my linux based 3CX PBX (fresh installs of the 3CX debian ISO from August 2nd 2018),
/var/lib/3cxpbx/Instance1/Data/Ivr/Voicemail/Data
There is a sub directory for every extension.
The file "greetings.xml" on many extensions which have a savevmgreeting.wav file stored is etiher missing completely, or missing the stanza:
Code:
<overrides>
  <greeting profile="default" file="savevmgreeting.wav" />
</overrides>

I updated all the erroneous greetings.xml to include this and now those extensions play their personalized voice greeting.
Make darn sure you have the permissions correct:
Code:
chown phonesystem:phonesystem greetings.xml
so that the 3CX system can properly manage the file in the future. :cool:
 
Last edited:
While I agree it would make sense to not regenerate the VM pin when it's not changing the length, I actually read the description and realized it would change the PIN so I didn't do it.
 
I think another question that should be asked is why is this new secure password length being introduced now? The system should have been using long and complex passwords for many years. When was it appropriate to use 6 character passwords?

I also agree that resetting the PIN was completely inappropriate.

Todd.
 
We just got hosed by this, too. Resetting the VM PIN seems completely unrelated to the insecure credentials, but at the very least this should be called out specifically in the "regenerate" dialog..
 
We just got hosed by this, too. Resetting the VM PIN seems completely unrelated to the insecure credentials, but at the very least this should be called out specifically in the "regenerate" dialog..

Problem will be solved.
It will be very granular in v16.
Look at the ui how google chrome offers you to clear cache - separating cache, files, passwords etc? 3CX regenerate password function will be like that. Completely granular and you can select anything you want to reset or keep the same.
 
Status
Not open for further replies.

Forum statistics

Threads
111,899
Messages
589,621
Members
164,765
Latest member
domi