V15.5 passing PCI Compliance

Status
Not open for further replies.

VictorC

SOHO User
Joined
May 1, 2017
Messages
150
Reaction score
16
Hi All, will updating to V16 fix the TLS 1.0 security

Here’s the info from the scan details:
THREAT REFERENCE

Summary:

Server supports TLS 1.0 protocol

Risk: High (3)
Port: 5061/tcp
Protocol: tcp
Threat ID: misc_tls_tls10

Details: A service supporting outdated versions of TLS or SSL was detected. TLS 1.0 and SSLv3 are affected by known flaws which could allow
man-in-the-middle attacks, such as
BEAST and
POODLE.
 
Under Settings -> Security scroll down and the last box allows you to enable PCI Compliance mode which basically only allows TLS 1.2.

Keep in mind that legacy phones might stop working.
 
Hello, thanks.. The box is checked.
 
You could always lock down 5061 to your SIP providers IP
 
Under Settings -> Security scroll down and the last box allows you to enable PCI Compliance mode which basically only allows TLS 1.2.

Keep in mind that legacy phones might stop working.

Unfortunately once could say this is labeled incorrectly. It only enables PCI compliance for the web server (nginx). The SIP TLS port the OP references is not affected by this setting.


You should just move 3CX outside of your CDE (which is what you should have done from the beginning) and don't worry about it. Isn't it funny that having an obsolete cipher on an encryption you don't use is bad but sending the SIP traffic unencrypted is ok :).

Anyways, I don't expect 3CX to do anything with SIP TLS until they finish the overall allowing TLS out of the box with LE and 3CX FQDN.
 
If it was me I would not worry about it at all, but what do you tell a client that's having a test done and the other party is saying that it's bad and needs fixed.
 
So be the better consultant and advise them. For maximum security as well as avoiding any potential future scan failures they should move 3CX out of the CDE. As long as this wasn't part of the original scope of work to you then this is billable time. If they don't care about real security and just want to pass the scan then block 5061.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,924
Messages
589,756
Members
164,796
Latest member
Dame24