Certificate not secure enough

Status
Not open for further replies.

doncol

Silver Partner
Basic Certified
Joined
May 28, 2021
Messages
33
Reaction score
6
Hi folks,
We have had a client advise that they believe the 3CX certificate in their Self Hosted install is not secure enough, and they'd like us to upgrade it.
Their request is to disable RSA encryption.
I have a few questions related to this.

1) Is there an updated guide to doing this somewhere?
2) Will this change with the impending v20 Upgrade?
3) Regardless of the timeframe set for the custom created certificate, will 3CX still auto-generate a new one through Let's-Encrypt anyway?

regards and thank you in advance,
Don C.
 
We have had a client advise that they believe the 3CX certificate in their Self Hosted install is not secure enough, and they'd like us to upgrade it.
Their request is to disable RSA encryption.
I mean RSA is the most widely used asymmetric algorithm out there, but ok. I'm sure the client has expert mathematicians and encryption people on staff.

I don't see any reason that using ECC or similar wouldn't work correctly, but I would tell the customer to forget about this request and stick with the official configuration if I were you.
 
I ran Qualys SSL Report on a PBX we've had installed for a few years now, one installed last year, and one installed last week.

The one from a few years ago got a B, while the other 2 both got A+.
Looks like the older one got a B because it supported TLS 1.0.

All 3 on v18u8.
I think the old one was installed with 17 and updated to 18, whereas the other 2 had 18 on install
 
I ran Qualys SSL Report on a PBX we've had installed for a few years now, one installed last year, and one installed last week.

The one from a few years ago got a B, while the other 2 both got A+.
Looks like the older one got a B because it supported TLS 1.0.

All 3 on v18u8.
I think the old one was installed with 17 and updated to 18, whereas the other 2 had 18 on install
security -> anti hacking -> bottom of the page turn off old ciphers

:5001/#/app/settings/security/4/anti_hacking
 
security -> anti hacking -> bottom of the page turn off old ciphers

:5001/#/app/settings/security/4/anti_hacking
I completely forgot that setting.
We had some older Yealink desk phones a while back that I had to enable the old ciphers for. Haven't used those desk phones in at least 2 years, but never went and reverted that setting.
 
Anyway, that aside now, I'm not quite sure why your client is requesting that...
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet