T48G EOL due to missing TLS 1.2

Status
Not open for further replies.

spaxxilein

Customer
Basic Certified
Joined
Mar 24, 2020
Messages
12
Reaction score
11
Hello,

we just updated to the newest version of 3CX Server and i missed the part that 50% of our phones are Yealink T48G phones which are now EOL and cannot be auto-provisioned anymore by the server due to "missing TLS 1.2" feature.

According to the documentation of Yealink of an older update x. 81.0.110 ( https://support.yealink.com/en/portal/docDetail?documentCode=886bf0f7b16e9862 ) the phone does support TLS 1.2 with this setting:

static.security .default_ssl_ method = 5

Can somebody please explain why we are locking out a perfectly fine phone which technically supports all necessary TLS standards from being autoprovisioned?

Thanks for your help,

spaxxilein
 
It's really a question of whether Yealink should still be used at all. Such behavior is a disgrace for the customer and the environment anyway. I will certainly no longer recommend Yealink devices if there is no rethinking here. Devices used to be used for decades and worked well. Today we throw away devices after three years? It really can't be at a time like this.
I mean Yealink is the market leader globally as far as amount of phones sold, lowest DOA / failures, feature set, options, etc. The T4xG series was replaced by the T4xS series in July of 2017 at the latest (maybe even earlier), so it's likely your G series phones are at least 5 years old and probably older. While I personally hate this is an issue and will need to come up with a plan to address in our customer base, at what point does a company say "you paid us $'s x years ago and the money for development of that product is "used up" now". Or, for all we know, the hardware may not physically be capable of x feature.

It's also not just Yealink. Snom, Fanvil, etc - all the older EOL models are no longer supported for provisioning over https with 3CX.
 
I mean Yealink is the market leader globally as far as amount of phones sold, lowest DOA / failures, feature set, options, etc. The T4xG series was replaced by the T4xS series in July of 2017 at the latest (maybe even earlier), so it's likely your G series phones are at least 5 years old and probably older. While I personally hate this is an issue and will need to come up with a plan to address in our customer base, at what point does a company say "you paid us $'s x years ago and the money for development of that product is "used up" now". Or, for all we know, the hardware may not physically be capable of x feature.

It's also not just Yealink. Snom, Fanvil, etc - all the older EOL models are no longer supported for provisioning over https with 3CX.
I'm also not talking about Yealink introducing a new feature or additional functionality like a new codec like Opus.
And there are certainly problems because TLS 1.2 is very complex in the specification. Nevertheless, the service life can often be significantly increased with relatively simple methods. And especially with telephones, it's really very simple. Nobody needs to tell me anything else. In my opinion, this is a purely economic decision by the company at the expense of our planet in the end.
There are other manufacturers who take a different approach with much more complex software and hardware.

Yealink maybe could also offer a paid update for example. Apparently this is not done because it makes more sense to sell a new device.
 
As a follow up on this, we tested this morning on 2 phones that worked last week a T46 and T48 , with the SIP TLS1.2 off, and a reboot, the phones still do not register via SBC or auto-provision. I will try manually here shortly, but not sure what the difference would be between auto-provisioned and manual unless the TLS1.2 is just on the config files?
 
As a follow up on this, we tested this morning on 2 phones that worked last week a T46 and T48 , with the SIP TLS1.2 off, and a reboot, the phones still do not register via SBC or auto-provision. I will try manually here shortly, but not sure what the difference would be between auto-provisioned and manual unless the TLS1.2 is just on the config files?

If they were already provisioned phones they should continue to work (register and make calls) so perhaps something else was the problem here.

You can delete the phone from the extension, factory reset it, and then assign it again making sure that the SBC is selected correctly in the drop down menu during the "Assign Ext" step.
 
I'm also not talking about Yealink introducing a new feature or additional functionality like a new codec like Opus.
And there are certainly problems because TLS 1.2 is very complex in the specification. Nevertheless, the service life can often be significantly increased with relatively simple methods. And especially with telephones, it's really very simple. Nobody needs to tell me anything else. In my opinion, this is a purely economic decision by the company at the expense of our planet in the end.
There are other manufacturers who take a different approach with much more complex software and hardware.

Yealink maybe could also offer a paid update for example. Apparently this is not done because it makes more sense to sell a new device.
the other option would be for 3cx to continue supporting the older TLS version, maybe as a selectable option. Then all the older phones from any of the manufacturers would continue to work.

BTW in the legacy phone system market, a phone set might never get replaced. A site coming from a legacy system isn't expecting to replace sets in 3-5 years. This is likely to be an issue when up against an Avaya Partner (IP or legacy) and they look at long term cost and ROI.
 
the other option would be for 3cx to continue supporting the older TLS version, maybe as a selectable option. Then all the older phones from any of the manufacturers would continue to work.


This option has existed for years now. We don't recommend it because it reduces your system security.

If you untick this in the Anti-hacking settings, it will allow you to provision the T48G.

But you might want to enable it again afterwards to maintain a high level of security

1664348683824.png
 
  • Like
Reactions: accentlogic and N_G
This option has existed for years now. We don't recommend it because it reduces your system security.

If you untick this in the Anti-hacking settings, it will allow you to provision the T48G.

But you might want to enable it again afterwards to maintain a high level of security

View attachment 32120
If this checkbox is cleared (feature disabled) then do the templates for the older phones, ex T48G, T29G, etc., appear in the phone provisioning list?
 
If this checkbox is cleared (feature disabled) then do the templates for the older phones, ex T48G, T29G, etc., appear in the phone provisioning list?
Nope, as the setting clearly states, it will change your TLS and Ciphers only.
 
Most of these phones are between 7 and 8 years old. Their EOL was 2 years ago. Thats a very different thing. Yes devices dont last 10 years anymore - does anyone of you still use a 10 year old iPhone or Android?

We have asked Yealink for a new firmware. But with the number of models they have its not easy, we understand that.

That said you can continue to use these phones for as long as you wish using manual provisioning. This is absolutely safe way to use them except that its not so easy to update any BLFs, true. But then again its a 8 year old device and new ones cost less then $100. Alternatively use local LAN provisioning (although its going to require split DNS in a future update)

You cant compare with Avaya either - back in their days these devices would easily cost $500. These 29G cost probably something like $50. And the Avaya phones are end of life these days too :)

And if we are talking about environment - older phones use much more power. Old phone systems even more.... And you can always use softphone apps where possible :)
 
  • Like
Reactions: pangel
Nope, as the setting clearly states, it will change your TLS and Ciphers only.
Well I had just finished thanking 3CX for this in another thread, but now I'm not so sure. Is there any way to import the templates so they will appear?

I hear what Nick is saying, and sure, he is the last work on this, but I'm going to suggest some things to consider anyway.
First is that these are desk sets, not cell phones. Businesses don't want to replace these without a compelling reason. That would be a financially positive outcome. And most business users aren't using any of the fancy new features on the phones. So we are not talking about upgrading phones to get some new feature or function, only to keep them supportable.
And this is key. You say you can manually re-provision them, but consider the real world. A company of 100 sets changes personnel twice a month, and they need their BLFs changed on every phone. That's 200 manual re-provisions every month. Even at 10 minutes a phone that's 33+ hours, even if it's once a month it's almost 17 hours. 2 solid days of support staff. And that's just one customer.

Now to replace all the phones it's $100 per phone, Customers may not want to pay this as many will be less than 5 years old. So that's $10,000 cost to the partner. Then there is the labor to replace the phones and provision, I'll keep that low and say 2 days labor. Then the big one, re-training all the users, 10 groups of 10, 2 hours each, almost 3 days.

So what your asking, and all I'm asking is that this be considered, is a solid week of labor and a degraded customer relationship, in a highly competitive market where margins are low to begin with.

And one final note. With the two possible outcomes, one being the customer replaces their phones and the other being they jump ship to another product. The first just maintains level for 3CX, you guys get nothing when the new phones are sold. And the second is a lost customer for both the partner and 3CX.

On the other side, backward compatibility would allow a dissatisfied customer of another product who already has T48G phone to move to 3CX. Most partners aren't making major % on the phones anyway, it's all about services. So this is all UP side.

The check box solves one problem, leaving in the templates would solve the other. No on wants 3CX to become less cutting edge or less secure, all we need to the option to fit the solution to the environment.

For anyone from 3CX, Thanks for your time.
 
Thanks for the feedback. I think i did not explain properly.

These phones are not secure to be provisioned via the internet with any system. Maybe other systems will not warn you, but its either because they are old or not secure. Going to another system is not a solution.

You can use these phones safely in following ways:
a. If locally provisioned on a network properly protected via a firewall.
b. Manually provisioned. Of course this is not practical if you actively use BLF buttons on the phones but many people do not. You can use the web client instead and its more effective than BLF anyway in my opinion.

Either way you should budget to replace these phones at some point.

This is the 3CX guideline, but if you want to override it on a DIY self hosted or on premise system you are welcome to do so by enabling the setting in the security section mentioned above. Of course you should be aware of the risks doing so. Its our responsibility to make you aware of the risks but ultimately its your own decision.

Now in some of the comments there is reference to these phones being 2 years old. This is not the case. They went EOL 2 years ago. On average I am guessing these phones are 5-7 years old. If you bought these phones brand new 2 years ago please contact your Yealink distributor how this happened.

I just wanted to defend/explain better a Yealink decision, which after all is a partner company. I think they have been good overall and instrumental in "opening up" a deskphone market which until a few years ago was pretty locked down and proprietary with each deskphone easily costing $300-$400 a piece.

I made the comparison with an Iphone or Android, but if you wish you can compare with a laptop or desktop. You can't use these for 10 years either. Companies write these down / off within 4-5 years. Ultimately an IP Phone is now an IT piece of equipment, no longer a telecoms / analog piece of equipment.
 
Last edited:
Is there any way to import the templates so they will appear?
Yes, custom templates (for the editions that support them) still work. So you can import the old EOL templates if you want and use them, but it will be unsupported technically. If you are having an issue you need 3CX support on you can always flip a phone to a supported template / provisioning method, replicate, and use that in your support case.
 
  • Like
Reactions: CentrexJ
Well it is what it is. :)

Anyone know which phones supported by 3CX have historically had the longest supported lifetime? If we are going to scrap the phones we might as well get the most out of the replacement.
 
These phones are not secure to be provisioned via the internet with any system...

You can use these phones safely in following ways:
a. If locally provisioned on a network properly protected via a firewall.
b. Manually provisioned. Of course this is not practical if you actively use BLF buttons on the phones but many people do not. You can use the web client instead and its more effective than BLF anyway in my opinion.
Hi Nick, hi all,

wouldn't the 3CX SBC be the solution ? It could act as a provisionning proxy.

Phone on LAN <--- HTTP only ---> SBC <--- HTTPS to the internet ---> Hosted 3CX

When provisionning the phone, we'll just point URL to the SBC LAN IP instead of remote one and SBC will secure and proxy the request to the 3CX provisonning server. It could also act as a caching proxy for address book, etc...

Julien
 
Hi Nick, hi all,

wouldn't the 3CX SBC be the solution ? It could act as a provisionning proxy.

Phone on LAN <--- HTTP only ---> SBC <--- HTTPS to the internet ---> Hosted 3CX

When provisionning the phone, we'll just point URL to the SBC LAN IP instead of remote one and SBC will secure and proxy the request to the 3CX provisonning server. It could also act as a caching proxy for address book, etc...

Julien

Thats also something i thought about - why arent the LAN phones provisioned by the SBC directly - instead they connect to the 3CX Server directly. This would allow "unsecure" TLS inside the LAN which naturally should be behind a firewall and still allow the usage of those phones.
 
  • Like
Reactions: kelsallp
We have good news in this regard. After discussing with Yealink, yealink have decided to update the firmware of these phones T29G, T46G, T48G. We have not tested yet but if all goes well then these phones will work with update 5 and beyond.
 
We have good news in this regard. After discussing with Yealink, yealink have decided to update the firmware of these phones T29G, T46G, T48G. We have not tested yet but if all goes well then these phones will work with update 5 and beyond.
Hi Nick,

wonderful news, thanks for caring and finding a good solution for this issue;)

Looking forward to the update and to test it ASAP.

Regards,

spaxxilein
 
  • Like
Reactions: AWS2P and N_G
We have good news in this regard. After discussing with Yealink, yealink have decided to update the firmware of these phones T29G, T46G, T48G. We have not tested yet but if all goes well then these phones will work with update 5 and beyond.
I came here to check on this and wow! This is great news. Once this is tested, will it take another update to get the templates back in or??
 
  • Like
Reactions: N_G
We have good news in this regard. After discussing with Yealink, yealink have decided to update the firmware of these phones T29G, T46G, T48G. We have not tested yet but if all goes well then these phones will work with update 5 and beyond.
Thank you for your persistence on this!
 
  • Like
Reactions: accentlogic and N_G
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet