Import csv with extensions web password v20

Status
Not open for further replies.

nettcom.augusto

Platinum Partner
Advanced Certified
Joined
Apr 24, 2023
Messages
6
Reaction score
0
Hello everyone!

After the update to v20 Update 3 (Build 786 Beta), the column for the extension web password was missing.

How should I proceed if we have a client with 3000 extensions, for example?
Which user generates the password? This is very delicate!

We always generate the password and send it to the client’s administrator to proceed with the installation of the 3CX Windows app.

Best regards,
Augusto Finger
 
Hi Augusto,

Here is what I can say... in the past, as a programmer, I could access all the passwords via the 3CX Call Control API. For all the reasons you can appreciate, this had to change. Now we have no access to passwords at all. The passwords are now encrypted and hashed. There is no way to interact with passwords anymore.

Could 3CX do it? Probably via some obfuscated c++ code somewhere, but 3CX has gone to great lengths (some of them very painful) to ensure the security of the platform. I'm not at all surprised that they removed the ability to import the password.
 
  • Like
Reactions: Evolute IT
We miss the option to generate the password hash ourselves. You can set it and use it with known passwords and change it later, but it would be nice to be able to generate it yourself.
 
I think the whole security effort is about obfuscating ANY access or information about how passwords are managed. The more information you can get, the greater the surface area for hackers. My guess is that this ability will not return, but that's only a guess. My advice is that you evolve your process.
 
  • Like
Reactions: Evolute IT
There is no problem anonymizing or hashing user access passwords in the system interface. However, when implementing a system for over 100 users, any process different from importing a list of names, numbers, emails, and predefined passwords for user login becomes a huge task. Once imported/created, there would be no issue in not having further access. If the idea of 3CX is to reduce the time the system administrator needs for management, I understand that this goes against that requirement. Making all users, from the most inexperienced to the experts, access their welcome email and create their own password will create much more work for the administrator. We always plan to deliver the system as ready as possible, so users can just 'plug and use.'
 
  • Like
Reactions: fxbastler
Making all users, from the most inexperienced to the experts, access their welcome email and create their own password will create much more work for the administrator. We always plan to deliver the system as ready as possible, so users can just 'plug and use.'
therefore
We miss the option to generate the password hash ourselves.
 
  • Like
Reactions: Ricardo.Monteiro
I would be very surprised if 3CX were to change how passwords are handled any time soon. They knew this change was going to be unpopular with some, but system breaches are unpopular too. They made the business decision to go with the lesser of the two painful choices.
 
Status
Not open for further replies.

Forum statistics

Threads
111,954
Messages
589,921
Members
164,851
Latest member
DrunkeMeister