RPS Security?

Status
Not open for further replies.

Adoltis

Customer
Intermediate Cert.
Joined
Nov 30, 2020
Messages
3
Reaction score
0
Hi All,

I understand the general gist of RPS servers provided by the likes of Yealink & Grandstream, but I am confused on the security aspect. As I understand it when provisioning a phone via 3CX among other things the Make, Model and MAC address is required. The MAC address and the provisioning URL is then sent to the RPS servers and so when the phone is reset and contacts the RPS servers it will be redirected to download its provisioning configuration file.

The above being the case is there anything to stop a miscreant from reprovisioning someone else's phones if they have the MAC address??
 
Nope, but it's not really that scary. Phones only hit RPS if they are in a factory defaulted state, and only one 'entity' can have the MAC address registered. So if someone tries to 'hijack' your MAC address after the phone is provisioned it wouldn't do anything unless you factory reset your phone. And if your MAC address is 'hijacked' before you provision the phone, you'll see the error in the 3CX management console when 3CX tries to register it with RPS and then you can just follow the manual instructions as the respective phone guides mention.

Besides, the RPS servers aren't open to the public. Depending on the vendor you either have to pay a decent chunk of change (I think Polycom was like $5k/year) and for eithers you can only be registered via distribution or by being an established partner with the vendor. Other's only let you register MAC addresses for phones you can proof you own as they will only register MAC addresses of phones purchased through official distribution channels.
 
  • Like
Reactions: CentrexJ
So do we need an RPS account with each vendor of phone that we use with our clients? We currently have a YMCS account with Yealink.

If as an example we purchased some used VOIP phones from eBay that had already been registered in the RPS system by someone else, would 3CX still be able to push out the RPS request? because from what I can see we do not need to link our 3CX instance to our RPS accounts with credentials or anything like that.

Kind Regards
 
It depends on how you want to handle things. In a perfect world, you let 3CX handle pushing devices into RPS as they have an account. But in doing so, you sacrifice some control as you can see by my signature link with a feature request to be able to purge MAC addresses from 3CX RPS control. For example if you setup a Yealink phone via 3CX and they register the MAC, it is in the system for two weeks and you can't add it to your RPS account. You may be able to open a ticket with 3CX to remove it, or with Yealink, but otherwise you are SOL.
 
Thanks cobaltit, I think it is making sense to me now. So the options are...

1. Send the RPS settings using the built in 3CX account, this will work providing the MAC address has not already been registered with someone else's account.

Or

2. Register the phone MAC address under our own RPS account and link 3CX to our RPS account.

Is my understanding correct?
 
Mostly. For the 2nd option, there is no linking. You add the device to your account. You provision the phone for STUN at which point 3CX will try to push the MAC into RPS (and fail). You ignore the warning to manually provision since you know why it failed. You plug the phone it and it works the same as if 3CX RPS had worked. Technically it works better/easier (although potentially less secure) because IIRC it will just provision vs requiring the phone to authenticate via extension and VM PIN as normal RPS via 3CX would.
 
  • Like
Reactions: nub
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,990
Messages
590,161
Members
164,925
Latest member
batarong