Update 7A - Focus on Security

N_G

Founder
Joined
Jun 6, 2006
Messages
4,857
Reaction score
9,290
Following our Security Incident we\'ve decided to make an update focusing entirely on security. We hope to release this update to QA in the coming days. We’ll then release an Alpha and Beta next week - with the final in the week following. Here’s what we’re including:

A BLF Panel in the Dialer of PWA “App”​

This featur...
Continue reading the Original Blog Post.
 
Sounds great. But, what about the feature to disable native login when using SSO?
 
If you want to use the legacy Desktop App you must provision it via PNP

Does that cover the legacy Windows Client also?

Does "legacy" in this case mean it is being deprecated/not developed like how the legacy Windows Client was designated?
 
Last edited:
  • Like
Reactions: Nathan@Voxtelesys
Does that cover the legacy Windows app also?

Does "legacy" in this case mean it is being deprecated/not developed like how the legacy Windows app was designated?
Please refer to this Blog Post
 
  • Like
Reactions: StylianosH_3CX
Hi Thomas, that post does not actually mention the "Electron" Desktop App is being discontinued...? It uses the word Legacy several times to refer to the Windows Client.

It also doesn't mention whether the Windows Client will need approval to connect.
 
We have not installed Update 7 on all of our installs. We stopped deploying Update 7 when Electron was flagged.
Does Update 7 need to be deployed before Update 7A or is 7A an all encompassing "7" Update.
 
We have not installed Update 7 on all of our installs. We stopped deploying Update 7 when Electron was flagged.
Does Update 7 need to be deployed before Update 7A or is 7A an all encompassing "7" Update.
If you go through the mgmt console to install updates then I imagine they will be installed cronologically.
 
Will the legacy app get a new way to provision for those that aren't on-prem? Without the config file only on-prem users can be configured with pnp.
 
Sounds great. But, what about the feature to disable native login when using SSO?
We are working on it, it would take longer so we are putting that in update 8

@SteveITS We are sticking with the electron based DesktopApp. There was some discussion in the heat of the attack but overall it makes sense to stick with the Electron based DesktopApp. It was not the architecture or the technology. To all intents and purposes it could happen to the legacy app too if we would continue to add features and develop it.
 
Will the legacy app get a new way to provision for those that aren't on-prem? Without the config file only on-prem users can be configured with pnp.
This is important.
 
  • Like
Reactions: Gasha
Thank you SO SO much for removing that user and pass from the welcome emails!
 
This is important.
Yes that was my next concern. Does it connect/PNP through an SBC? It is possible to use the Desktop App if not on-premises, i.e. self hosted, or for staff working from home?
 
The desktop app to use is PWA, followed by Electron app. You can use the legacy windows client but it needs to be provisioned using PNP, we will not be making additional provisioning methods for the legacy client.
 
The desktop app to use is PWA, followed by Electron app. You can use the legacy windows client but it needs to be provisioned using PNP, we will not be making additional provisioning methods for the legacy client.
1681285210852.png

I hope it's not the "refresh to allow it to be our super sub for years to come" you was talking about.

It sounds like a rather big change. Can you please explain in greater detail, what this means in production? Will already provisioned legacy apps needs to reprovisioned? Will this work behind any SBC?

Please take into account, that we're using that legacy app in RDS environments to control it via CTI.
 
  1. Before logging in, users must set a password first.
Can you please provide more details on this?. Now when weclome email does not include web pass (imo this was no.1 feature to move to 3cx)
 
  1. Before logging in, users must set a password first.
Can you please provide more details on this?. Now when weclome email does not include web pass (imo this was no.1 feature to move to 3cx)
I am pretty sure that it's something along the lines of entering your DID and or E-Mail Address and being asked to create a new password instead of just "enter did/mail address, copy-pasta the password and press login" I don't see any issues with it.

Sure, the users might have to remember the password they've chosen for themselves, but as an admin you can still reset it for them just as usual. That's just my guess...
 
Will the legacy app get a new way to provision for those that aren't on-prem? Without the config file only on-prem users can be configured with pnp.
VERY Important!

We have plenty of clients that use DATEV and the Legacy App incl. the plug-in for it in an RDP environment and have been doing so for a very long time, their 3CX's are off-prem and they use an SBC, I wonder how that will be handled then? I hope we're going to be presented some concrete information about this going forward.

This was a huge breakpoint and selling factor, when we were competing with other offers, appliances and providers...
In my eyes, it's currently one of, if not THE best, solution for cases like these, as the v18 App doesn't offer much in ways of integration and similar.
 
Will see about that.
I think there are way to much big changes on each update. I think it started with U2 and with U6 with web client admin.
 
  • Like
Reactions: TiagoC and Gasha
VERY Important!

We have plenty of clients that use DATEV and the Legacy App incl. the plug-in for it in an RDP environment and have been doing so for a very long time, their 3CX's are off-prem and they use an SBC, I wonder how that will be handled then? I hope we're going to be presented some concrete information about this going forward.

This was a huge breakpoint and selling factor, when we were competing with other offers, appliances and providers...
In my eyes, it's currently one of, if not THE best, solution for cases like these, as the v18 App doesn't offer much in ways of integration and similar.
We are adding DATEV / TAPI support to our Desktop App. The update got pushed back a little but its coming quite soon after we put this security issue behind us.
 
We are adding DATEV / TAPI support to our Desktop App. The update got pushed back a little but its coming quite soon after we put this security issue behind us.
No way! Good stuff!

This is both great and very heavy news, if this is actually true and you honestly mean it, then thank you.
For real now, this is what a lot and if not most of us, have been waiting for, for a VERY VERY long time.

In the long run, it'll will make so many things so much simpler, with added customer satisfaction, both on your and our part.
 

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet