Announcing 3CX on Debian Buster Technical Preview

  • Thread starter Thread starter KyriakosP
  • Start date Start date
Status
Not open for further replies.
I'm not having a single issue with buster and SBC.

In fact since moving to the pi4 hardware we are having less issues with SBC's in total.
 
  • Like
Reactions: N_G
@Nick W - thanks for the headsup! We have done a lot of work in that area and we are doing some more resource usage improvements in the coming month or two.... The new Raspberry 4 with 8 gigs will be sufficient for small to medium installs as a PBX and for SBC also for larger installations
 
Do we will have to upgrade each 3CX and SBC to Debian 10 with a complete reinstallation or that will be possible through a 3CX update?
 
No it will be a completedly automated process, like an update....
 
No it will be a completedly automated process, like an update....

Thank you for your fast anwser, seems to be dumb question but i asked anyways to be sure.
 
  • Like
Reactions: N_G
Its a good question! And and important one. We do all the auto updates and this is why we require that no changes are made to the machine and it be dedicated to 3CX so that the upgrade process can be guarantueed.
 
Last edited:
Guys,

Don't know if this is the right place, but struggled with a new Intel NUC 10 (https://www.intel.co.uk/content/www/uk/en/products/boards-kits/nuc/kits/nuc10i3fnk.html) to get configured as SBC using Debian 10.

It appears using this link: https://downloads-global.3cx.com/downloads/misc/debian-10.5.0-amd64-netinst-3cx.iso will pick up the inbuilt NIC ( Intel® Ethernet Connection I219-V ) but only give me the option to install 3CX not SBC.
Any ideas?

Previously used this link: https://downloads-global.3cx.com/downloads/misc/debian-10.4.0-amd64-netinst-3cx.iso (was on the Debian Buster preview link previously) but this doesn't pick up the inbuilt NIC.

Also tried Debian 9 pre-built ISO, but hit Graphical glitches once I hit Install (also experienced this on some of our newer VMWare 6.7 hosts - fix was to drop VM Workstation level down to 6.0 instead of 6.5/6.7).

Hoping to use these Intel NUC's for our client's as SBC's.

Thanks
Tom
 
  • Like
Reactions: accentlogic
So my first answer for any and all security concerns is don't put 3CX in a network if you have any compliance concerns as 3CX has never posted anything to this fact. It has been mentioned by 3CX that they update the OS but I don't know of any evidence or statement as to time frames, severity, etc. In my experience 3CX itself has generally been secure so typically we don't worry about it for smaller customers, and especially since most installs start in or are moving to the cloud. But for anyone that asks the type of questions you ask I put it outside the network of concern. We've also manually run updates without any ill effect (to date) but 3CX advises against it. So I would plan on doing one of those two options unless 3CX commits to a published stance on this.

@YiannisH_3CX @JohnS_3CX Has there been anything stated or will there be as far as OS updates/security patches?

PS. Glad to see someone doing their homework!
 
  • Like
Reactions: accentlogic
I'm a new customer and the designated administrator of our 3CX server (16.0.1078 Enterprise Annual). I've been using this tech preview since October 2020 and so far everything has been working perfectly - very impressed so far.

However, I have questions in regards to your policy and process when it comes to security updates for debian packages (from the official http://security.debian.org/ repo). I see that there are several packages being version pinned (via /etc/apt/preferences.d/3cxpbx) - which isn't uncommon depending on the reasoning for the particular package which I assume you do have several reasons for. Nonetheless, I temporarily moved this file and ran "apt update" to see what packages have security updates from the repo, if any. There are currently 8 packages with pending security updates but running apt update with the pinning file in place won't report that updates are available and subsequently can't be updated.

As the sysadmin responsible for this Linux system (and representing other customers/partners of yours like me), what should I typically expect for the cadence (or "turnaround time") of security updates being released in the official repo to when they are available to be installed in your custom Debian build?

Additionally, does the severity of a security issue an update is meant to address determine when you authorize it for release? In other words, lets say there was a remote code execution vulnerability in nginx with a CVSS of 8 reported on Monday, a security update released to the repo on Tuesday... assuming no issues are found during your internal testing, when would I see it as available to be installed on your Debian build?

I'm trying to get an idea of how 3CX handles this so my Director of IT knows what to expect for compliance and security posture - and so I know that I don't have to go rogue to install security updates in a timely manner.

Forgive me if there's a better place to ask this - I would appreciate being pointed to the appropriate venue if so.
Hi there!

First off, I am really glad to hear you are enjoying our product!

In regards to the pinned packages, we test each one of our releases with the latest packages at the time of testing, while also though staying mindful of how these package updates may affect PBXs on previous service packs.
Generally we will update the pinned packages around the same time when there is a 3CX Update for maintenance purposes.

There are though cases where a critical vulnerability is found. Our Security Team monitors this regularly (we also have our Hosted PBXs to look after) and if something is found, we will take action to check the package, see how it may affect the current and previous versions, and update the pinned files.
 
  • Like
Reactions: accentlogic
Status
Not open for further replies.

Forum statistics

Threads
111,991
Messages
590,167
Members
164,929
Latest member
Cloudstar