V18 Alpha 3 - Fixes and Features

Status
Not open for further replies.
@AlanRamsay Its the same one there is now, there is no specific v18 one....
 
@AlanRamsay Its the same one there is now, there is no specific v18 one....
Great - we’ve got 18A3 deployed with some rPIs running the old version without any issues; just wanted to check we were testing the correct thing.
 
  • Like
Reactions: N_G
Hello,

i tried to install the v18 Alpha 3 from the ISO image, but if im ready with the debian setup and the system reboot is done, there is no 3cx installation, just a login command. Any idee what to do ?

Thanks
 
Hello,

i tried to install the v18 Alpha 3 from the ISO image, but if im ready with the debian setup and the system reboot is done, there is no 3cx installation, just a login command. Any idee what to do ?

Thanks
This usually happens when the machine does not have internet access, because it tries to get information from the repositories online and it fails, so it just prompts you to login.

Try checking the network settings and the VMs access to the internet, then try rebooting the machine or repeat the process.
 
  • Like
Reactions: ekasjanov
I upgraded our test instance from Alpha 2 to Alpha 3, and then enabled 365 User sync. Below is a screen shot of what happened to existing users mobile and outbound caller id fields. PM me if you need any more details.

View attachment 21678
Just an update, this shall be fixed by the time V18 is final.
 
  • Like
Reactions: accentlogic
@Nick Galea
1) Thanks for the awesome work you are putting into your product!
2) Can you please consider SAML integration at least for SSO and additionally for provisioning. The amount of Iaas platforms out there that people are adapting is growing exponentially, ie Okta, Onelogin, Azure etc etc.
 
  • Like
Reactions: Giuseppe Ravasio
I stumbled upon this on the Snom website:

With the version 18, 3CX decided to end the support for specific TLS v1.2 cipher suites, and to simplify the DNS configuration with its DNS Helper feature. These changes prevent the M700 - a product that has been declared end of sales/support (EOS) June 2020, after 6 successful years in the market by us - to be auto-provisioned and to register to the 3CX SIP server when updated to V18.

The M700 is EOS and there will be no further firmware updates.

Local installations​

The only way an M700 base station can be provisioned and registered on 3CX V18 is to switch off the DNS Helper feature, and use the provisioning method Local LAN. Any other provisioning method will request an HTTPs connecting to the 3CX server and therefore fail.

We host all our 3CX servers in our private cloud for our customers does this mean our customers can trow away all their M700 dects. Our can we manualy connect the M700 to the 3CX cloud server without provisioning?
 
I stumbled upon this on the Snom website:

With the version 18, 3CX decided to end the support for specific TLS v1.2 cipher suites, and to simplify the DNS configuration with its DNS Helper feature. These changes prevent the M700 - a product that has been declared end of sales/support (EOS) June 2020, after 6 successful years in the market by us - to be auto-provisioned and to register to the 3CX SIP server when updated to V18.

The M700 is EOS and there will be no further firmware updates.
Hi!

The decision to not update the Cipher Suites the M700 devices use was made by snom, after we had notified them about this some months ago. To be clear, we suggested to snom to release a new firmware with support for the new Cipher Suites, but we were told that this is not possible for an EOS device due to hardware limitations.

[EDIT]
I have just found out that snom has issued a rebate for the M700 for users of 3CX, where you get the M900 as a replacement at some discount. What you need to do is send an email to [email protected] with subject "M700 Exchange" and briefly explain the situation. This offer is exclusive to 3CX partners and is valid until 31/05/2021.

You must understand that we as 3CX must provide and guarantee a secure solution for all our customers and to do this, we must rely on the latest TLS versions and Cipher Suites.
I really do feel for the customers and partners that will be affected by this, but reducing the security of our software because 1 device of 1 vendor did not release a security update for their device was not an option for us.


To explain a bit better how the situation is, the M700 does not have the necessary Ciphers to be able to "talk" to 3CX V18 over TLS, which means provisioning using a HTTPS link will not longer be possible. In turn, that means that STUN and SBC provisioning will not be possible.


We host all our 3CX servers in our private cloud for our customers does this mean our customers can trow away all their M700 dects. Our can we manualy connect the M700 to the 3CX cloud server without provisioning?
While manual provisioning is an option, although not supported or recommended, you could do it, and already configured devices should continue to work with issues, HOWEVER, the Phonebook will stop being updated and any changes you make in the management console will not be passed onto the device.

Other options:
  • Tell your users to try out the 3CX Mobile Apps!
  • Move the install of your customer on-premise and configure M700 as Local LAN
  • Suggest to your customers to upgrade to the M900 which supports the needed SSL Cipher Suites (possibly also the M300 with a new firmware that is being prepared)
  • Establish site-to-site VPN between the customer location(s) and your Private Cloud and register the M700 devices over that, effectively making it a "Local LAN" setup.
 
Couldn't wait for the general release... are we close yet? We are also waiting for one of our server (ESXi v.7xx) to be ready sometimes next week, would be perfect timing if 3CX v18 official out by then and I could do some official testing on the new hardware too!!! Finger cross
 
@MannyL - Thank you for the headsup. You mention Azure - fully supported. 95% of our customers that have a user directory, use Active Directory. You can move to Azure AD free of charge and this is then fully supported by 3CX in all editions.

If you dont use Active Directory, you can use Microsoft or Gmail signon (presuming you have 365 or Gsuite, but its not even required). Else you can stick with the tried and tested and working absolutely fine option of storing the password in the browser.

Onelogin at 2 euro per user per month - really? Thats more than the 3CX license. Its easy to throw around website names and integrations but its a lot of work to develop, keep up to date and support all these providers and their implementations of multi vendor standards such as SAML. The reality is that few people use these services. But feel free to open up an idea on ideas forum and lets see how many votes it gets.

@jamesnb - go ahead and install the alpha, you can update it when the final comes available! But it wont be next week this i can tell you :)
 
@Nick Galea I agree with @MannyL about the need for 3CX to support the SAML Standard. Don't be too focused on the cost; many of us are using products (Such as Horizon with VMWare Workspace ONE Access or Citrix with Citrix Workspace) that bundles solutions relying on SAML to offer a true SSO experience for the user (going from VDI to Terminal Services but allowing SSO to Office365, Salesforge and many many others)
That could be great for anyone that wants to deploy 3CX to a large userbase by simply publishing the app in the company portal (i.e. Workspace ONE) relying on said portal for the authentication security (2FA, geolocation or any rules the administrator wants to enforce!).

I would be glad to open an idea about SAML, but I'm not allowed!
 
  • Like
Reactions: Evolute IT
I stumbled upon this on the Snom website:

With the version 18, 3CX decided to end the support for specific TLS v1.2 cipher suites, and to simplify the DNS configuration with its DNS Helper feature. These changes prevent the M700 - a product that has been declared end of sales/support (EOS) June 2020, after 6 successful years in the market by us - to be auto-provisioned and to register to the 3CX SIP server when updated to V18.

The M700 is EOS and there will be no further firmware updates.

Local installations​

The only way an M700 base station can be provisioned and registered on 3CX V18 is to switch off the DNS Helper feature, and use the provisioning method Local LAN. Any other provisioning method will request an HTTPs connecting to the 3CX server and therefore fail.

We host all our 3CX servers in our private cloud for our customers does this mean our customers can trow away all their M700 dects. Our can we manualy connect the M700 to the 3CX cloud server without provisioning?
I have just found out that snom has issued a rebate for the M700 for users of 3CX, where you get the M900 as a replacement at some discount. What you need to do is send an email to [email protected] with subject "M700 Exchange" and briefly explain the situation. This offer is exclusive to 3CX partners and is valid until 31/05/2021.

I would urge all snom M700 users that use 3CX to inquire, as the M700 is EOS and will be receiving no more updates.
 
@Nick Galea I agree with @MannyL about the need for 3CX to support the SAML Standard. Don't be too focused on the cost; many of us are using products (Such as Horizon with VMWare Workspace ONE Access or Citrix with Citrix Workspace) that bundles solutions relying on SAML to offer a true SSO experience for the user (going from VDI to Terminal Services but allowing SSO to Office365, Salesforge and many many others)
That could be great for anyone that wants to deploy 3CX to a large userbase by simply publishing the app in the company portal (i.e. Workspace ONE) relying on said portal for the authentication security (2FA, geolocation or any rules the administrator wants to enforce!).

I would be glad to open an idea about SAML, but I'm not allowed!
So people are using Citrix and Terminal Services but not Active Directory according to you? Didnt even know that was possible but definitely there are not a lot of those companies. Use the Active Directory SSO.
 
  • Like
Reactions: ewebster
It's obvious that Modern VDI Users are using AD (and many also sync to Azure AD) and we would love to be able to provision AD users.
Also in many cases we tend to have a complex product like vmware workspace one or citrix workspace that is a sort of MMDM/ID manager that integrates SSO for external apps through SAML

If you don't trust my word ( which is crystal clear from your answer :-( ) trust vmware or citrix one:
https://techzone.vmware.com/resource/what-workspace-one
https://www.citrix.com/en-gb/products/citrix-workspace/
 
@Giuseppe Ravasio Then i dont understand your point. We fully support 365 and Azure AD for SSO so these customers are fully supported by our choice for SSO
 
@Giuseppe Ravasio Then i dont understand your point. We fully support 365 and Azure AD for SSO so these customers are fully supported by our choice for SSO
SAML is easy to support and doesn't require you to test with multiple providers. You can just implement it and make it "it's there but we can't help much".

SAML can allow any type of SSO, whereas O365 and GSuite are pretty much very specific and may not be used by a company. I've seen that a lot too.
 
  • Like
Reactions: Giuseppe Ravasio
@Giuseppe Ravasio Then i dont understand your point. We fully support 365 and Azure AD for SSO so these customers are fully supported by our choice for SSO
@Nick Galea, as @Frederick Marcoux said O365 and GSuite are very specific (I would add very simple and very closed) and they are directly used mainly by SMB (more small than medium to be honest).
In many complex setups and especially when a company invest a lot on VDI and TS, product like Workspace One are involved.
Their main focus is identity management but also MDM and Mobile or BYOD devices enrollment.
One of the features that everyone is loving so much about those identity managers is that that can be used as a central authentication point and that they have a lot of rules for the authentication; For example you can force a 2FA check only on specific conditions, you can avoid 2FA for trusted networks, you can forbid authentication from untrusted devices or devices that doesn't meet specific criteria (Updates, OS Version, Geolocation).
When a user is authenticated in the identity manager (IDM) he could access company applications from the IDM (and here you can customize the experience for every scenario). From here the applications (VDI, TS, SaaS, ....) can be started without further authentication.
This is only a brief description of what enterprises are doing in this field that Azure AD cannot and isn't meant to do.

To be accessible and integrated in this kind of deployments SAML and maybe OAuth support is needed (along with AD user provision).
That something you need to support to be considered as a complete UC solution for enterprises.
VDI, idM and MDM are a fast growing market with many new deployments and I think you're missing a big chance here.

I hope to have explained my point to you.
 
SAML is easy to support and doesn't require you to test with multiple providers. You can just implement it and make it "it's there but we can't help much".

SAML can allow any type of SSO, whereas O365 and GSuite are pretty much very specific and may not be used by a company. I've seen that a lot too.
Agree, I used to work for one of the largest VAR's in the US as a pre-sales solutions architect. I ran into many customers (usually startups) that didn't have AD/LDAP at all. They usually relied fully on cloud first solutions like Okta or Idaptive for Idp. Usually they had a mindset of Microsoft is evil and would avoid there solutions too. But at the same time with working with those customers I didn't find one startup that wasn't using O365 or Gsuite. Not to say the world is only on those two solutions... With some of the political climate in the US I've known some people to be interested in dropping certain cloud things as well.

I'd say it's not a bad idea to look at a way to more so integrate directly into an Idp's eco-system as a ready setup app. But in the world of 80/20 efficiencies can 3cx capture 80% of the SSO userbase for there product on the way they want to do it at 20% or less of the effort? I've noticed most SaaS offerings are going the way of adding a button for Gsuite/Microsoft and doing it the easy way vs building some complex SAML Idp mechanism since that is the majority of the market for business authentication.
 
  • Like
Reactions: NickD_3CX and N_G
I'd say it's not a bad idea to look at a way to more so integrate directly into an Idp's eco-system as a ready setup app. But in the world of 80/20 efficiencies can 3cx capture 80% of the SSO userbase for there product on the way they want to do it at 20% or less of the effort? I've noticed most SaaS offerings are going the way of adding a button for Gsuite/Microsoft and doing it the easy way vs building some complex SAML Idp mechanism since that is the majority of the market for business authentication.
In your experience of this 80% how many ends up having O365/M365 license with Teams included for "free"?
In my experience they are more than 50% and growing; thus they probably will never be interested in 3CX.
On the other side, the 20% cannot even deploy Teams at all.
 
  • Like
Reactions: Cjay
In your experience of this 80% how many ends up having O365/M365 license with Teams included for "free"?
In my experience they are more than 50% and growing; thus they probably will never be interested in 3CX.
On the other side, the 20% cannot even deploy Teams at all.
Good point Giuseppe. I've worked for a company where I had teams and just my cell phone for 5 years.

Though I don't know if it's the area that I'm in but what i've seen for startups and SMB's is some mix of tools. I've seen ones that have o365, don't touch teams and use slack, zoom and things like ring central or 8x8 or just there cell phones. Also one VAR was pushing shoretel forever ago so the established ones are looking at mitel cloud to get off there legacy shortel things, just because that is what the VAR is pushing. They also tend to go to a VAR/MSP and let the VAR/MSP jam whatever they want there way where they don't investigate. Also usually they hate teams... When I was at this huge VAR we were such a Cisco shop we had E3/E5 licensees of O365 but we used everything as Cisco for Collaboration/Telephony. We'd also push Cisco heavily to customers.

I currently have teams at my job and it's phone enabled. We use it as the chat/collaboration platform of choice. But we use 3CX for telephony as teams is missing many common telephony features that we need or just is poorly executed still where things that are basics just do not work. Reporting is still way missing. We are a phone heavy organization with call rules, reporting and teams just would not cut it. It doesn't even integrate to track calling for contacts, leads, companies in Microsoft Dynamics CRM... Which we also use.

But if you just need a basic telephone, that works as a telephone where you aren't multitasking and you still don't get texting then the all in one teams route might be right for you.
 
  • Like
Reactions: Giuseppe Ravasio
Status
Not open for further replies.

Forum statistics

Threads
111,973
Messages
590,078
Members
164,896
Latest member
sameage