3CX v15 TLS Secure SIP Settings & Cert

Status
Not open for further replies.

pickaat

Joined
Nov 21, 2014
Messages
8
Reaction score
0
I decided to implement secure sip on one of our pbx's but the guide that is up on the 3cx website is out of date. However, I noticed that in the settings secure sip is enabled and have an already pre-defined certificate already available so i decided to use it.

My question is, how secure is this certificate,is it randomly generated or is this just a general place holder.
 
It used to be the case that for assistance with secure SIP 3CX would encourage you to contact support for setting this up however under the new rules regarding support I am not sure.

Either way I know there has been rumour that at some point secure SIP will be included with the PBX as standard, which would be good.
 
well, from my little experience of using it (my way) for about a month now, here is what I found out:

>the certificate seems to be linked with your fqdn if you are using 3cx's domain services
>the certificate is linked with your maintenance, expiring a day before the date in your management console
> setting it up on Yealinks are pretty much straightforward using their old guide. However, you will have to provision the phone twice because 3cx sends the port back to 5060 instead of 5061 and reverts it back to udp from tls. This will cause you to redo this step again before it sticks... a minor annoyance

either way would be nice to get some more word of their vision for secure sip and their means of up keeping it.
 
My question is, how secure is this certificate,is it randomly generated or is this just a general place holder.
The certificate is the same you used for your FQDN. If this is a 3CX provided FQDN then it is a Let's Encrypt certificate. You can use the certificate to provision devices via TLS however this takes some manual configuration.
 
either way would be nice to get some more word of their vision for secure sip and their means of up keeping it.
Please note that we are working towards improving TLS provisioning and how that is done. Please follow out blog post for further updates.
 
Status
Not open for further replies.