3CX server hardening on Debian platform

Status
Not open for further replies.

Kane Wong

Free User
Joined
Oct 13, 2018
Messages
233
Reaction score
9
Hello;

In my 3CX Debian distribution, I realize that the server come with a self signed X.509 certificate like this C=SE/O=AddTrust AB/OU=AddTrust External TTP Network/CN=AddTrust External CA Root and using SHA-1 With RSA Encryption as hashing algorithm. In order to do server hardening on this distribution, can I remove this self-signed certificate from the server in order to minimize the man-in-the-middle attack?

Also, how could I exclude sensitive HTTP headers from server responses that revealed server software information, including the following:
• PHP/7.2.6
• Apache/2.4.33 (Unix)
• OpenSSL/1.0.2o

Is there any negative impact on 3CX running if I close those vulnerability.
 
Hi Kane,

The PBX is provided to you as-is, in the form that it has been tested to work. Making the changes you propose would put you in unknown territory and may cause the system to not behave correctly. It might be best to just protect it behind a good firewall.

I will not make any assumptions about your level of expertise, so I would simply say this general statement to anyone reading this:

Unless you have the deep knowledge, expertise and experience to fix your own problems when you make these changes, then do yourself a favor and leave the system as is because we will not be able to help or provide support on modified installations.

I hope this puts things into the right perspective!

PS: You also mention some packages that 3CX does not use, not sure why those are on your machine..
 
Last edited:
Status
Not open for further replies.