3CX FIPS Compliant?

jpauley

Silver Partner
Advanced Certified
Joined
Feb 19, 2025
Messages
4
Reaction score
0
We have a client that must adhere to FIPS (Federal Information Processing Standards) compliance. I’m looking to verify if 3CX v20 can meet these requirements, specifically regarding the use of FIPS-validated cryptographic modules for signaling (TLS) and media (SRTP).

  1. Does 3CX utilize NIST-validated modules for encryption, or does it rely solely on standard OpenSSL libraries?
  2. If the underlying OS (Debian 12 or Windows Server) is set to FIPS-enforced mode, will 3CX v20 continue to function correctly?
  3. Are there specific configuration steps or supported hardware (SBCs/Phones) required to achieve a FIPS-compliant 3CX deployment?
Any insight or official documentation on this would be greatly appreciated.

Thanks!
 
Short answer: 3CX is not FIPS 140-2 certified at the application level as of V20, and has not publicly pursued FIPS certification.

What you can do in a compliance-sensitive environment:

1. OS-level FIPS on Debian Linux: Enable FIPS mode using the kernel FIPS=1 boot parameter and fips-mode-setup. This forces OpenSSL into FIPS-approved algorithms, which 3CX inherits via system crypto.

2. TLS and SRTP: 3CX supports TLS for SIP signaling and SRTP for media. Configure strong cipher suites (AES-256, SHA-256+) to align with compliance requirements without needing formal FIPS cert.

3. Windows FIPS policy: Enabling FIPS via Local Security Policy can cause TLS handshake failures depending on how the .NET runtime interacts with the SIP stack. Test in a lab first.

For FedRAMP or DoD environments, 3CX is not the right fit. For commercial compliance like PCI-DSS or HIPAA, TLS plus SRTP with strong ciphers is typically sufficient.
 
  • Like
Reactions: accentlogic and N_G

Members Online Now

No members online now.

Forum statistics

Threads
111,835
Messages
589,289
Members
164,667
Latest member
Infinity Network