As am also shocked. You seem to prefer to argue instead of understanding the reasoning presented. Let's break it down.
I am really shocked !
I comment, just in case someone at 3CX thinks, that Cobaltit's opinion is the only one:
Your original post said you asked gold and titanium partners and they don't use it on their internal networks at the clients. So thus I'm clearly not the only one. I'm just one of the more vocal ones because I'm tired of people complaining that 3CX doesn't do something that it does in fact do.
And that's why people buy products like 3CX:
They expect to get good software side support for "special things like SRTP/TLS provisioning".
Otherwise they can use Open Souce Asterisk solutions which perform well....
As far as I know, 3CX uses encrypted tunnel when using the mobile App, Windows- or Webclient, but not on normal phones or DECT/Fax GW's.
You and I have both stated that the software components that 3CX has direct control of fully support encryption. And 3CX does support encryption between itself and trunking providers as well as endpoints but that is dependent on 3rd parties and the installer's level of knowledge which 3CX can't control.
So, You want to say:
"https: is not a "regulatory requirement" or mainstream: So why should people ask for it?"
Are you serious?
Now you are just putting words in my mouth or perhaps it's just something lost in translation. I never said people shouldn't ask for it. My statement that it is not mainstream or a regulatory requirement has to do with economics which is the primary motivator for parties to come together to make something work. You keep mentioning HTTPS so let me give you an example. HTTPS has been around for ever but it wasn't until LE came out and gave away free certificates that there was a tremendous growth in adoption over the last few years because the economics (free) and the technical requirement was lowered.
You may talk about phone systems good enough for the USA......

Have you ever managed to spy 25 year old European E1 lines or Alcatel 4x64KBit ISDN on 2-wires!!! proprietary lines?
I haven't managed because you need real expensive equipment.
But I managed easily to spy on SIP calls.....
Equipment expense is not a limiting factor. A motivated person could just as easily steal the equipment. And exactly the same way as unencrypted SIP, your examples are relying on access, not encryption, as the limiting factor. For your example, where you spied on SIP calls, were you inside the network you are trying the secure or were you sitting outside on a pole 6 blocks away?
Again: Do you do your online-shopping with HTTP ?
If not, please explain what tinfoil 'trust-no-one' you are.
I ask you for the attack vector you are trying to protect against and this is your response? Well I want to thank you for proving my point. HTTPS is there, particularly in your online shopping scenario, for a couple reasons:
- It's mainstream.
- It's a regulatory requirement (PCI)
- Economics because the penalties for not adhering to PCI compliance outweigh the costs for complying.
You may speak for your 'unknowing cients'....
If I would ask some of your clients / some top 500 CIO/CEO, whether he thinks, his phone conversations within the company should be protected at least as well as his online shopping, I might get other answers / requirements from him.....
Where to start on this..... So first off, CEO/CIO's say many things, like "I had no knowledge of this illegal thing or that inappropriate thing", etc so what they say, and what they act upon is two entirely different things. Heck how many CEOs/CIOs got sacked/resigned after major breaches in their credit card systems which they were (supposedly) much more concerned about securing. And like your HTTPS to SIPS/SRTP comparison your example here is apples to oranges. You are comparing internal traffic (topology not withstanding) to external traffic (online shopping). And then there's the fact that the CEO doesn't care about the HOW. Protecting via VPN, and other readily available and known reliable methods achieve the goal. But since you have the ears of CIO/CEOs, please let me know how the conversation goes when you tell said CIO/CEOs the reason they keep having audio issues (as you confirmed in another post) is because you decided to configure TLS/SRTP vs using one of the other tried and true methods.
Oh.... so all your clients have each of their internal phones connected with a VPN tunnel?
So I think you misunderstood what I meant by internal requirement. Internal requirement as far as what company policy dictates as to how your voice traffic should be handled as opposed to an external requirement (PCI, HIPPA, etc) not specifically internal traffic. But yes we do have scenarios where we are using VPN on the phones themselves (many of the supported phones support this) for 'internal' phones but this from back in the SIP Proxy days when it was garbage and was mainly for ease of provisioning/accessing remote phones. For for true internal phones, it's separate network/VLAN with ACLs typically but for more secure environments full on firewall/traffic inspection since that's a requirement now for PCI and other standards so we often already have the pieces in place.
That's unfortunately true and this will never change, as long as people like you - who have some knowledge and influence - continue to flame "tinfoil" on people like us.
Well thank you for believing I have the kind of influence to change the behaviours of LECs, transit providers and other entities but unfortunately I don't. If I did, I'd post on here even more because I could quit my day job! That scenario will change when the economics force it to, and not before.
We were waiting for 1 year, paying a 128 concurrent call license without using it, always waiting for 3CX to get their SRTP/TLS working !!
After 1 year, we gave up but keep on dreaming that 3CX will finally make it!
I see we get down to the root of the problem perhaps?. Were you the person who made the decision to purchase 3CX without doing proper testing/homework beforehand and this is where the angst/frustration is coming from? If you had come here on the forums or talked to partners prior to purchase we could have educated you and set appropriate expectations.
And I know the people at 3CX are great !
And they will make it work in the future !
This is something we agree on it seems.
So please:
- Stop de-motivating 3CX staff and
- Accept, that people like us, asking for SRTP/TLS, are not stupid !
Best Regards from
Tinfoil George
So again, I have not the influence you think I have with 3CX. But I will say I think I help 3CX staff by setting reasonable expectations for how 3CX should work and, often bluntly, saying the things they can't say as a direct employee of 3CX . And I don't need to tell people they are stupid, they make that obvious themselves. In this particular case I didn't call you stupid, I was correcting your factually incorrect statements about what 3CX does and doesn't do. Continuing to argue in the face of those facts can be construed as stupid but I leave that interpretation up to the reader.
My Footer:
No need for "Earn Crypto in your Sleep" Advertisement in my footer,
no certified, no nothing.
If you need help setting up a footer properly there are many folks on the forum that can help with that as well.
