- Joined
- Jan 4, 2019
- Messages
- 14,530
- Reaction score
- 3,701
Can you provide us with some more info on this?Upgrade of clients site last night to 18.0 (Build 917) lost all Global contacts.
Can you provide us with some more info on this?Upgrade of clients site last night to 18.0 (Build 917) lost all Global contacts.
The client had global contacts yesterday on old version and then after upgrading last night they were gone this morning. As in empty like there was never any added in the first place. The contact's area was blank. They don't have Microsoft or CRM contacts. Let me know if you need more info.Can you provide us with some more info on this?
You still have the possibility to choose passwords.from user view is this still uncomfortable because he has to think a passwort and has to save this separatly.
Therefore it should be the possibility to enable the passwords in the welcome emails again.
+1
Hi @tronic,The client had global contacts yesterday on old version and then after upgrading last night they were gone this morning. As in empty like there was never any added in the first place. The contact's area was blank. They don't have Microsoft or CRM contacts. Let me know if you need more info.
That's good to know thanks. The client luckily had a recent copy that used to import.Hi @tronic,
Did you manage to get sorted with this issue? I had the same for one of our self-hosted linux PBXs, Support advised that the only way to fix it is re-enter the contacts, as the data is stored within a table in the database.
I pulled the phonebook.xml from a pre-upgrade backup (in the provisioning folder) and once converted into the correct format, it imported through the console. The xml file is only an export of the data, so overriding the file does nothing as it is overwritten when the contacts are edited.
Ive tried on a few of ours and it works fine with 10. Don't enter more.Hello, whe update yesterday our server to this version, but today when we update our 3cx clients we see the inconvenient of can´t create 4+ conferences. Onle can have 3 persons on call conference, beyond that we face the error "invalid email".
Can help us
This has been solved, https://www.3cx.com/community/threads/v18-8-build-935-big-issue.122435/#post-573730Ive tried on a few of ours and it works fine with 10. Don't enter more.
Are you using legacy no rsvp?
Thats not completely correct because 3CX sends email via TLS to another Email Server so the email transport is secure for sure!You still have the possibility to choose passwords.
The passwords being now hash with a Salt , it is irreversible (or almost / not to say "impossible". ).
Generate the passwords yourself and create the extensions with the CSV file.
Find another way to communicate the passwords but not by e-mail in clear text.. which would be completely contradictory ; your need secure password approach ..and finally communicated in an insecure way.
It's a bit like the bank mailing you a credit card, pre-activated, with the PIN code written on a piece of paper in the same envelope. Without having the possibility to change their PIN. Result ; Anyone who gets their hands on the envelope can use it as they want..
However, to meet your challenges, maybe, a solution allowing you to view the password only once via a URL.
Equivalent to what OneTimeSecret proposes.
Of course, this would involve storing a copy of the plaintext password temporarily (when creating it before it is hashed) in the database (for a limited time), which is again contradictory but not as risk as an email.
The problem remains the same, if someone intercepts the email, they will have access to everything until the real recipient reports that they cannot see their password (URL already in use)
The fax machine <-> the fax machine! It's definitely the future!
Use Fax machine to send passwords to users on their own unattended physical fax machines,
I'm obviously kidding, I'm not making fun of you @bit101 , I promise, I'm kidding about the fact that it is complicated to communicate sensitive information securely.
Cheers,
The negative with any security effort is it always loses simplicity for the client. I don't think anyone would doubt that the passwords in the email was convenient and easy for all.I am indeed convinced by all his arguments; there are both advantages and disadvantages to encrypting passwords or not encrypting them.
In the end, all of this becomes secondary if OAuth authentication is configured.
Perhaps the solution to satisfy everyone would simply be to suggest/ask 3CX to add support for other OAuth authentication methods? I find it hard to believe that a company, in 2023, uses no system that could also serve as an authentication method.
I'm not trying to spark a debate.
Kind regards
Indeed, I follow you 100%…
The only real next step would be 2FA. This is the only thing that a client can't do something stupid with the password.
…
And in any case, we recommend SSO! This is the best and most secure.
2FA yes its on our roadmap although you can get it today using SSO using Google or Microsoft SSO.
You can also switch this off if you want to as long as you’re using a VPN, local provisioning or another RPS server for example. To do this you will need to go to the Management Console >> Settings >> Parameters and search for RPS_LOCAL. Once there, set the value to 0. Existing installs do not need to do anything as the value is already set to 0!
Founded in 2005, when VoIP was an emerging technology, 3CX has gone on to establish itself as a global leader in business communications.