Security PCI Compliance SSL / Cipher Security option not working?

Status
Not open for further replies.

ServiceIIT

Customer
Joined
May 20, 2020
Messages
4
Reaction score
0
Hello,

we are running the latest 3CX (auto update on) 16.0.5.611 and the option to disable TLS 1.0 1.1 to have compliance seems not to affect the webserver settings.
What can be checked to get that setting working?

SSLsecurity.PNG

I've set / unset the option in the security settings, and rebooted the system with no effect.
Even gone ahead and edited the nginx.conf to have ssl_protocols TLSv1.2; because in there were also 1.0 and 1.1 set
TLS 1.0 and 1.1 is still on when we analyse our IP:5001 - for example I used https://www.cyphercraft.io/tls to check. What do you use?

OS/System: Local machine with Debian 9.1
Linux pbx3cx 4.9.0-4-amd64 #1 SMP Debian 4.9.65-3+deb9u1 (2017-12-23) x86_64 GNU/Linux

Any suggestions are welcome.
Thanks Alexander
 
Are you sure you're pointing it to the right place? I just used that tool against our 3CX instance and got this:

1591326757849.png

And if I'm reading this right it seems to indicate it's using TLS 1.2

I tried another tool and it shows this which seems to confirm:

1591326919147.png
 
I think I'm pointing it to the right location ;) , pointing at: external-IP:5001
Here is my screenshot:
Capture.png
 
Hmm.. not sure. Some sort of proxy in front of it perhaps? I spot checked a couple other instances and they all provided the same results as what I posted for our instance.
 
Thank you for your answer.
I just realized that I get different results when I use the IP address or DNS name.
With the IP address I get TLS1.0 1.1 1.2 enabled
With DNS only TLS1.2 - How comes that?

How did you test it (IP, DNS?)?
Could you share the other side you did the test against your instance, please?

Thanks Alexander
 
A quick follow up: It seems the https://www.cyphercraft.io/tls will give a false positive when used with external-IP:5001.
So to be 100% sure I removed in the nginx.conf the TLS 1 and 1.1 strings
I've verified with Nmap the results.

Additionally I needed to disable all CBC ciphers.
I've done that by adding !SHA1:!SHA256:!SHA384 to the ssl_cipher string.
I hope it will not interfere with the Certbot.
 
Status
Not open for further replies.

Forum statistics

Threads
111,953
Messages
589,910
Members
164,845
Latest member
tdzski5