Recent pentest showing 'Insecure SSL/TLS Configuration' on 3CX - SHA

Status
Not open for further replies.

rcanpolat

Customer
Basic Certified
Joined
Oct 6, 2022
Messages
40
Reaction score
3
A recent pentest has found the below on our onprem 3CX server. Any advice on fixing this and any cons on fixing? Running latest version of the Debian 3CX VM.

Screenshot 2023-06-26 104538.jpg
 
Hello @rcanpolat,
Thanks for reporting this, in fact that's something we are aware and are planning to address in a future version with the introduction of TLS 1.3 so old ciphers can then be dropped, for now those have been kept for interoperability purposes with legacy devices.

That being said, if you scan with tools like Nmap or Qualys SSL Labs, with the current ciphers/transport configuration of our webserver we are still ranked with an A+ so these are rather minor/theoritical issues at the moment...
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet