Does 3CX v18 include security updates v16 doesn't have? (Debian based)

Status
Not open for further replies.

stormgoose

Trainee Partner
Basic Certified
Joined
Jan 15, 2021
Messages
40
Reaction score
26
I'm aware that with the jump from 3CX v16 to v18 that the underlying Debian OS jumps from v9 to v10.

What is unclear from all change logs I've read on the 3CX website is what the security implications are of the new release. Are recent security patches, particularly of the underlying OS, only included with the v18 update? Or are these still included, as needed, for v16 for now?

This brings me to a greater question - I've never got my head around how the OS security patches are managed anyway. Does the Debian OS just silently get on with these in the background independent of the 3CX Server Web App running at a higher level? Or are OS updates only ever initiated and installed under the autority of the 3CX Server Web App, and Debian's native patching system is disabled?

My reluctance to update my clients to v18 is because I'm on leave presently, and don't want to invite problems with a new update when the system is presently stable, as long as it doesn't pose a security threat.

Cheers
 
One thing , do not update the system via logging into the console.

3CX will install any operating systems updates required , just need to have 'Automatically update 3CX' ticked under Updates

Check out - https://www.3cx.com/docs/manual/installing-debian-linux-pbx/

  • Do not install other packages or change the configuration.
  • Do not install system updates via the command line! This is done by the 3CX system via updates after they have been tested!
  • Any changes to the system will render your installation unsupported!
 
  • Like
Reactions: N_G
Thank you for that advice @Saqqara, but that's not quite the question I was asking. I have no intention of manually running updates as I assumed this would mess things up royally :)

To put my original question more compactly - now that v18 is out, will it only receive underlying security patches, or will v16 still receive security updates too? Is there any way of knowing when 3CX has installed security patches solely for the OS, or when they've been included along with other 3CX patches?

One of the biggest things that concerns me with 3CX is the lack of info on security patching. The only change log that I've seen is for feature updates and bug fixes. Perhaps I've missed something, but this is of ongoing concern, as the security of the system is paramount above everything else.

After testing a v18 Beta build a month or so back and it getting hacked within about 6 hours (the hackers would have been able to make calls through SIP Trunk if I hadn't had it disabled), the point became extra relevant. I reverted to v16. I got in contact with 3CX, and they messaged back that a security patch had been released to deal with this, but there was zero record about this on the 3CX website which did little to reassure me!
 
Hi @stormgoose,

This is similar to this post: https://www.3cx.com/community/threa...lled-via-automatic-updating.79651/post-367011

As for Security updates via 3CX for Deb 9, our focus is beginning to shift to Deb 10 with v18 so it's advised to slowly start upgrading your PBXs to Deb 10 for all of the latest security updates.
Thanks - will check that out now. In short, is v16 still receiving basic security updates, and on what time scale will this continue? I'd like to update my clients to v18 when I'm in a better position to be at hand if there are any problems. Cheers :)
 
Hi @stormgoose,

on what time scale will this continue?
I can't say but I'm quite confident that there will be a communique mentioning the phasing out of security updates for Deb 9. Keep an eye on the blogs, your mail and the forum for future updates regarding this.

I'd like to update my clients to v18 when I'm in a better position to be at hand if there are any problems.
Sure! Not critical right at this moment.
 
@VasilisV_3CX Scarily, according that to the link you sent it says:

"1. If the "Automatically update 3CX" option in the "Updates" section of the Management Console is disabled, then Debian Security updates are never performed by 3CX. Not even when you manually update 3CX by downloading and installing the updated from the Management Console's "Update" section."

This is terrifying as this is unticked in my client's install - does this mean that the install of 3CX will be behind on underlying OS security patches back to whenever the server was first installed with a base version of v16?

If I've read the further detail correctly it sounds like I have no choice but to tick "Automatically Update 3CX" and that when I do it will just update to the now released v18, so I guess all told this negates any way of installing OS security patches for v16, as I mustn't do it manually so there's no mechanism :-(
 
I can't say but I'm quite confident that there will be a communique mentioning the phasing out of security updates for Deb 9. Keep an eye on the blogs, your mail and the forum for future updates regarding this.
OK - so in practical terms if I can't manually update Debian security patches from SSH shell, and if I can only get updates to the Debian OS by agreeing that the system will automatically install new patches (which includes the now 3CX v18 RTM) how do I update OS security patches for Debian 9 in a way that won't break the system and won't install 3CX v18?

Cheers
 
Hi @stormgoose,

does this mean that the install of 3CX will be behind on underlying OS security patches back to whenever the server was first installed with a base version of v16?
Yes, you should probably enable that on all of your installations.

If I've read the further detail correctly it sounds like I have no choice but to tick "Automatically Update 3CX" and that when I do it will just update to the now released v18
No, this applies patches and hotfixes but no major updates. The major updates will appear in the PBX update section instead.
 
  • Like
Reactions: stormgoose
Hi @stormgoose,


Yes, you should probably enable that on all of your installations.


No, this applies patches and hotfixes but no major updates. The major updates will appear in the PBX update section instead.
It's just it says on the update page:

"3CX "RELEASE" updates will also be downloaded and installed automatically. If the update is a "Alpha/Beta (unstable)" update, then this will not be automatically installed and must be installed manually if needed. Alpha/Beta updates are used to evaluate an upcoming version before it is officially released and should be used for testing and evaluation purposes. Do not install Alpha/Beta updates on your production systems.

I take the word 'release', especially mentioned alongside the seperate handling of Alpha and Beta updates, to mean a major version release - but am I misinterpretting this? This wording says to me that v18 will be installed automatically now that it's out of Beta and into RTM!
 
Or is the context of 'release' a point version update - for example if 3CX (hypothetically) had released a v16.5 update to version 16?
 
3CX does not auto upgrade major versions, so enabling automatic updates, in theory, should make 3CX apply any OS updates to bring you current. But if you are really worried about it, then you can do a package audit to confirm. The other option is to make a backup and do a fresh install from the Debian9/v16 ISO which should bring you current. Or just go enjoy your vacation and worry about it when you come back :)
 
  • Like
Reactions: stormgoose
3CX does not auto upgrade major versions, so enabling automatic updates, in theory, should make 3CX apply any OS updates to bring you current. But if you are really worried about it, then you can do a package audit to confirm. The other option is to make a backup and do a fresh install from the Debian9/v16 ISO which should bring you current. Or just go enjoy your vacation and worry about it when you come back :)
Many thanks for the input. Would you happen to know any meaningful commands I can run from the 3CX web based terminal (or an SSH terminal) that would give me an output of key packages installed and perhaps an overall Debian build number I can validate is current somewhere? I appreciate the different components in the Debian OS that 3CX will be utilising will be broad, so not sure the best way to present and check meaningful info.

I turned auto updates on to run yesterday, but literally have zero way of knowing whether it installed any OS patches (it doesn't look like the VM restarted, so guessing not as security patches would have probably triggered a reboot post install?)

Cheers for your help
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,977
Messages
590,098
Members
164,906
Latest member
Nari