- Joined
- Sep 13, 2022
- Messages
- 10
- Reaction score
- 2
Hi 3CX Staff Team,
We are planning a 3CX V20 deployment on Windows Server for a banking customer.
Due to the bank's security policies, the environment is highly restricted and the PBX is intended to operate primarily within the internal corporate network.
The current environment/requirements are:
Could you please help me clarify the following:
Best regards,
We are planning a 3CX V20 deployment on Windows Server for a banking customer.
Due to the bank's security policies, the environment is highly restricted and the PBX is intended to operate primarily within the internal corporate network.
The current environment/requirements are:
- 3CX V20 on Windows Server.
- The customer uses their own custom FQDN.
- The FQDN is resolved internally to the private IP address of the 3CX server.
- Internet access from the server is restricted due to banking security policies.
- The customer has an internal PKI/CA infrastructure.
- They currently use an internal/self-signed certificate solution based on their corporate Web Server certificate template.
- The certificate is not issued by a publicly trusted CA.
- Corporate/domain-joined clients can trust the internal certificate/CA through the bank's managed environment.
- Using a publicly issued SSL certificate may be restricted by the bank's security policy.
Could you please help me clarify the following:
- Can 3CX V20 WebRTC work with an internal/self-signed certificate, assuming the certificate and CA chain are fully trusted by the client OS and browser?
- If the certificate contains the correct custom FQDN in the Subject Alternative Name (SAN) and the browser shows the HTTPS connection as trusted without any certificate warning, would this be sufficient for WebRTC to work?
- Does 3CX specifically require a certificate issued by a publicly trusted CA for WebRTC, regardless of whether the customer's internal certificate is trusted by all corporate endpoints?
- If a publicly trusted certificate is mandatory, what is the 3CX-supported solution for a banking/internal environment where Internet access is highly restricted and the PBX should not be publicly exposed?
- Would the following architecture be supported?
Publicly trusted SSL certificate + Custom FQDN + Internal/Split DNS → Private PBX IP
In this scenario, the FQDN would resolve to the private 3CX IP for internal users, and the PBX/Web Client would not need to be directly accessible from the public Internet.
Best regards,