PCI security

Status
Not open for further replies.

wizards

Silver Partner
Basic Certified
Joined
Mar 30, 2010
Messages
20
Reaction score
0
What are the implications of turning off the "PCI" security check box.

I have a customer who realise on Remote Phone Book, and the current release has blocked this for all their phones. I believe that is rectified in release 6. Meantime, as there's no relevant firmware for their phones, the only solution appears to be turning off PCI. I've checked this does solve the problem. I just wonder what it's actually doing, what level of risk they may be open to if this is disabled.

The 3CX server is behind a firewall, we can actually block the HTTPS port completely if we have to.
The customer does not use the phone system for credit cards, indeed I don't believe they take credit cards in any way, which would be I assume the primary reason for a "PCI" compliant setting. I'm just wondering if something else is bundled in with it that we might regret disabling.
 
It enables older versions of TLS and specific ciphers suites. These versions are widely considered insecure and will cause you to fail a PCI scan (among others).
For older phones that don't support modern TLS standards, this will be the only way for them to be fully functional.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet