Update 7A - Focus on Security

These are all great initiatives team 3CX.

Is there plan to implement 2FA? That would be a crucial feature to increase security on management console and partner portal.
 
@Gasha - Yes its true and i apologize for it taken so long for us to do it! We we're nearly done actually then the supply chain baseball bat hit us. Once we get up we will finish and test and release...

@KonnectCraft Yes we are discussing it, its much requested and i agree it makes sense....
 
The desktop app to use is PWA, followed by Electron app. You can use the legacy windows client but it needs to be provisioned using PNP, we will not be making additional provisioning methods for the legacy client.
Hi Nick,

Sorry to beat this horse but the blog post only refers to "legacy Desktop App" and your answer refers to the legacy Windows Client...will BOTH need the PNP setup or just one of them?

Thanks,
 
if we are talking about our security wish list, I would love to see MFA introduced, but most clients we push to SSO and for admin we set longer 32+ character passwords.

Not knowing how insanely difficult this would be it is likely a future version, or a bottomless rabbit hole.

I have a few more wish list items but time and place [insert winky face emoji]
 
  • Like
Reactions: N_G
Hi Nick

Most of our clients like legacy desktop app more than web client.
The problem with pnp provisioning is it does not work if you are on a different network.
What if the 3cx is in the cloud or if client is out of office?
 
Hi Nick

Most of our clients like legacy desktop app more than web client.
The problem with pnp provisioning is it does not work if you are on a different network.
What if the 3cx is in the cloud or if client is out of office?
Will VPN work for you in that instance?

Also note that V16 won’t be supported forever, only this security incident gave it a few more months of life, if 3CX would rather remove the V18 Desktop app, there is no way they will support the V16 app long term
 
@SteveITS - only for the legacy app as its not being rebuilt so for that you need PNP and only for local network can it be used.
@Sparky Bear - I fully agree with SSO!
@cyberspot - out of the office you must use the Desktopapp....
 
only for the legacy app as its not being rebuilt so for that you need PNP and only for local network can it be used.
OK thank you. Can I suggest the blog post be corrected? The wording "legacy Desktop App" is bound to confuse and/or alarm a lot of people...

Edit: also, will already-provisioned legacy Windows Clients continue to work?
 
Last edited:
Will you be adding Steal Focus to the PWA? Users moved onto it are finding the lack of that challenging!
 
No unfortunately not, you will need the Desktop App for that. Users must click on the push notification to bring window to front.
 
@SteveITS - only for the legacy app as its not being rebuilt so for that you need PNP and only for local network can it be used.
@Sparky Bear - I fully agree with SSO!
@cyberspot - out of the office you must use the Desktopapp....
"Out of the office you must use Desktopapp". Nick, we've got hundreds of long time clients using the legacy windows app offsite, remote to the pbx. I understand we'll have to force them to webclient, pwa or desktop app. We'll have pushback. Please consider reviewing the Manager view in the old windows app. That is what they all like. There is a lot of info in that view, all on one screen. IVR/Calls, extension list, queue lists with agents. It's multiple windows or scrolling in the web app to see the same data. That's why many of our clients haven't made the switch to web or desktop app. Thanks. Of course I also realize it's just a learning curve too and people don't like change. :)
 
  • Like
Reactions: autohaus
Old installs will continue working you just can't provision new ones via email... Switchboard we have in new desktop app. They will have to get used to new way I am afraid - we can't maintain lots of apps.
 
  • Like
Reactions: GregG_3CX
Old installs will continue working you just can't provision new ones via email... Switchboard we have in new desktop app. They will have to get used to new way I am afraid - we can't maintain lots of apps.
Once provisioned, will the legacy app work off-lan via the 3CX tunnel (like it currently does today)?
 
@Nick Galea I'm pretty sure you collect metrics on usage of 3CX systems and if not I'm sure you could. The topic of clients comes up a lot in the forum and the answer is often bandwidth to maintain multiple apps, perhaps sharing the utilization of each client installed as percentage of total clients installed would clarify for those questioning it's eol. I know we have the Ideas forum but there's a lot in there. Publishing the percentages, it would be pretty clear what the demand was for a particular client. This won't answer everyone's questions or demands but would let them know where they stand across the whole installed base and afford us some much-needed fresh air after this client-based incident... Thanks again Nick for the focus and support...
 
@SweetAction - Yes no problem at all. Its just that we have to remove the configuration file from the email for security reasons. @illcsales - We don't track actually but at this point not sure it will change much. We need to get update 7a, 8 9 out of the door before we can even talk about our client strategy. We want to be the most secure PBX by design and procedures once again and this is where our team will focus on in the coming months
 
We have still been waiting with updating, can anyone confirm that everything is stable and secure for us to update?
 
The 3CX server was never an issue. The updated, new certificate .425 app was released a week or so ago.
 
@Nick Galea, @3CX_devteam, more or less related to security topic, but please put the following packages back into your 3CX Debian packages repository :
snmpd
smartmontools

We absolutely need them to properly monitor our 3CX servers...
Thank you very much for your support & understanding !
 
@Nick Galea, @3CX_devteam, more or less related to security topic, but please put the following packages back into your 3CX Debian packages repository :
snmpd
smartmontools

We absolutely need them to properly monitor our 3CX servers...
Thank you very much for your support & understanding !
You can alway add a repo source and manually install them,

If I may ask, what do those packages give you?
 
Would have to add default Debian repo to have these packages available, which would be a mess, as 3CX repo is a Debian "frozen" and "shorten" one.
snmpd : used to monitor the server through SNMP : CPU, memory, swap, disk usage, processes... The most common way to monitor a production server...
smartmontools : used to monitor physical disks (SMART status, bad sectors...), and as a result mandatory on a physical production server...
It then makes sense to have then back into the 3CX repo.
 

Forum statistics

Threads
111,974
Messages
590,081
Members
164,899
Latest member
mazet