V20#1494 Manually set DECT Web Console Password

Status
Not open for further replies.

Gavino

Customer
Joined
Jul 24, 2021
Messages
41
Reaction score
16
It seems that for DECT Web Console Password, I can only "Reset Credentials" but not set to the password I want.

1705985431824.png
I'm guessing this is a new security feature? I appreciate 3CX trying to improve security by adding a secure password generation tool. What I don't appreciate is being forced to use that password, and not the secure password I deem appropriate for myself.

By all means keep the "Reset Credentials" functionality, but please allow me to set the password in this field, like I am able to do in v18. Thanks.
 
How come? How often you going to go in to the base?
 
Understand your point here however in this way we ensure that secure password is always in use.
 
How come? How often you going to go in to the base?

It's a DECT multicell system - so base stations (plural). If you know anything about DECT, you know that there is a small number of simultaneous calls that can happen on any one base station at any one time. Sometimes the base stations get unbalanced when one or two reboot but others don't. By "unbalanced", I mean that some of the base stations have almost no SIP registrations (the ones that rebooted), while others have dozens. When that happens, we usually end up with call quality issues, and sometimes people are unable to make or receive calls due to base station overload (during busy morning periods).

We log in regularly as part of routine maintenance to check this SIP registration balance, and also when troubleshooting call quality issues. Then we know whether or not we have to schedule a multi-cell chain reboot after hours (or during work hours if urgent).

And when I say "we", I mean myself (IT manager) and the General Manager (who likes to get his hands dirty from time to time). We have three sites all with multicell, and it's easiest to set the DECT password to the same at all three sites. It's a randomly-generated non-guessable strong password, and we have rotated it in the past.

The short answer is - I log in regularly.


Understand your point here however in this way we ensure that secure password is always in use.

That is true. How about just doing password strength validation, same as with user password resets?
 
Well it seems that your issue here is more related with Multicell getting unstable and you should focus there. Meaning that you might need to check this with the vendor and not have to always login and troubleshoot.
But in any case this will not change as we will randomly create those passwords.
 
Just use a password manager and you'll never have to remember a password again :D
 
Well it seems that your issue here is more related with Multicell getting unstable and you should focus there.

If I didn't have to log in, I wouldn't. I have already been down that path, looking for any SNMP data that would tell me the SIP session(s) for each base station, but alas it doesn't seem that the information can be gleaned that way. It's been a while - I should snmpwalk and take another look at that, but I doubt that anything has changed.

Just use a password manager and you'll never have to remember a password again :D

Don't presume I don't already, as I have been using one for decades. It's just that:
(a) I would rather have just the one DECT password rather than several
(b) I want the ability to set it to what *I* want to use, and not what 3CX tells me to use
(c) I don't want the extra administration of relaying to the GM what passwords are for what DECT base stations. I just want "the" DECT password.

My main full time profession is actually Cybersecurity (vulnerability assessment and forensics). I think I can be trusted to set a good password. To be clear - I actually use an open source password generator on a separate air-gapped device with known entropy and where I have vetted the code - that's how seriously I take passwords. In my 30+ years in IT I have found several password generators where the "random password" is not very random, due to poor entropy. It's my own personal policy that I always do my own password generation. So when another system tries to shove password generation down my throat - of course I take umbrage to that. I don't tell you how to chew gum.

But what does it matter? If it's a person's own system - they should be able to set something like "cat123" if they are that daft - it's there system after all. Just have a password complexity checker and give a warning if you feel like you need to hand-hold anyone.

Think of the scenario where someone clicks on the "Reset Credentials" button. There is no confirmation dialog of "Are you sure you want to reset the credentials?"... it just changes, pretty-much instantly. What if that click was an accident and I want to have it as it was previously? There is no undo button.

This is unnecessarily rigid and not well thought out. If it doesn't get fixed and restore the V18 functionality, people will just remove the provisioning link from the base station and manage it manually, so that the "Web Console Password" will be meaningless, except after first provisioning before it gets changed on the base station.
 
Does 3CX have a REST API I can use to poll all the data in the "#/app/phones" page? I noticed that the "IP" column contains the IPv4 addresses of the actual DECT base stations. If I could pull down all that data into our NMS I can parse out the IP and use that to get the # of SIP registrations on each base station and flag any that are overloaded. Ta.
 
Does 3CX have a REST API I can use to poll all the data in the "#/app/phones" page? I noticed that the "IP" column contains the IPv4 addresses of the actual DECT base stations. If I could pull down all that data into our NMS I can parse out the IP and use that to get the # of SIP registrations on each base station and flag any that are overloaded. Ta.
No API at the moment.
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,972
Messages
590,066
Members
164,888
Latest member
Tim Cook