webclient blocked due to base 3cx.us domain ssl expired

loyer

Silver Partner
Advanced Certified
Joined
May 5, 2016
Messages
107
Reaction score
46
A client's access to the webclient is being blocked by their security software due to the base 3cx.us domain's SSL certificate being expired 912 days ago. You can see this here: https://www.sslshopper.com/ssl-checker.html#hostname=3cx.us

I explained that the full webclient URL's SSL certificate was not expired and valid. For whatever reason, they feel this is a security issue. Their exact response is listed below.

Would it be possible to renew the SSL certificate for 3cx.us ?


The website is being blocked due to the company needing to update their ssl certificate. According to the information when I pull the address their certificate is expired by 912 days. Our recommendation would be to reach out to the company and make them aware that they are using an invalid or old web security certificate on their base web domain (this would be the 3cx.us). We can certainly add an exception for the web address which would bypass this block; however, we would need to ensure you are aware that such an exception would make it possible for nefarious individuals/groups to deliver a false version of this web application to you potentially exposing the device to a data breach. Below is a screenshot of the advanced details from the pages security warning. We would need to complete the exception on each device as this is completed within each computer and not at a network level. Please advise how you would like to proceed.
 
Yikes, classic "I have no idea what I'm doing but I found a thing and that must be it" on their part.

You can't show them that the two hostnames go to different IPs/web servers?

Another way would be for 3CX to point 3cx.us to a non responsive web server, then you (well, hopefully!) should be able to tell this client that web server no longer exists so is no longer an issue.

Is the block from their network out, or from the a/v company's side? Meaning, can the client just block access outbound to those IPs and the a/v software can't see the expired cert?
3cx.us. 299 IN A 216.239.34.21
3cx.us. 299 IN A 216.239.38.21
3cx.us. 299 IN A 216.239.36.21
3cx.us. 299 IN A 216.239.32.21
 
The security consulting firm is in the financial industry and I guess very protective. They understand that it is a separate domain / IP but still feel that somehow this is a security concern. All of my client's traffic goes through their client software as well as their network / proxy / firewall. Neither I or my client has any way of adjusting it ourselves. I have requested they apply an exception for my client's domain but they will need to apply it to every workstation.

I was hoping this could be an easy fix for 3CX to use Let's Encrypt and put this on auto-renew and call it a day. :)
 
This shouldn't be an issue now, however as already mentioned, the top level domain is not used anywhere for anything.

For this to be an issue, a user would need to click on a link and consciously choose to ignore an invalid certificate while having someone performing MiTM or DNS poisoning in his local network. This is true no matter if a certificate is valid or not, in order to perform MiTM over HTTPS.
 
Thank you! I appreciate you resolving this issue so quickly.
 

Forum statistics

Threads
111,818
Messages
589,167
Members
164,642
Latest member
davids86