TLS 1.2

Status
Not open for further replies.

AP370

Free User
Joined
Jan 31, 2022
Messages
3
Reaction score
0
Hi,

by scanning the SSL-certificate I get an notification that TLS 1.2 with CBC-Blockchiffre-Modi (Cipher Block Chaining) is weak. I have allready activated the Option to TLS 1.2
Enable PCI compliance SSL/SecureSIP Transport and Ciphers (This will leave only TLSv1.2 enabled and may prevent old legacy phones and old 3CX Apps to connect remotely to your system). Requires SIP service restart (Go to Dashboard, Services, Select 3CX PhoneSystem 01 SIP Server and restart).
does anybody know, if I can activate TLS 1.3 in 3CX?
Thanks!
 
Hi @AP370,

At the time of writing this, no.
 
Thanks for the fast answer. Is there a possibility to deactivate the CBC-Suites in TLS 1.2?
 
Not natively in 3CX. Is there a specific compliance target you are trying to acheive?
 
Hi @VasilisV_3CX ,

I was searching for problems linke this since 15.01.22, but it seems that was a few days to early.
As in this Post you mentioned this problem appears by scanning for PCI-DSS and the scan of Qualys failed with this CBC-Suites. PCI-DSS is required for accepting credit cards and so I am searching for a solution to pass the scan and extern clients can access 3CX.
Manually dissable the CBC-Suites is a bad idea (future troubles)?
 
Hi @AP370,

I'd like to invite you to email our dedicated security team on [email protected] as they'd be better equipped to answer your question with absolute certainty.
 
Last edited:
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,901
Latest member
Silent_Guru