¿ªÔÆÌåÓý

ctrl + shift + ? for shortcuts
© 2025 Groups.io

Re: AUTH and SSL on 3 Series


 

Systems with remote access are typically the ones that require AUTH+SSL most. Less of a concern if the user's mobile device is utilizing a secure VPN to their network, but when the system was set up with port forward/mapping AUTH+SSL and secure ports are absolutely needed to prevent DOS attacks and rogue connections.

If "Mobile" means the legacy "Crestron Mobile (Pro) (G)" app, then FW v1.503 with AUTH ON & SSL ON (with legacy SSLv3 fallback enabled) is needed for secure MobileProG connections (FW rollback requires syntax "PUF FileName.puf -ALL").??

Otherwise, even if Force Auth Mode is enabled (due to CA-SB327 compliance needed w/ newer 3-Ser & x60 FW and newer 4-Ser & x70 device models), you can still disable SSL in most cases. This essentially leaves you with a password protected processor that still accepts only nonsecure device connections. Though that typically isn't necessary (except with some legacy stuff like MobileProG) since SECUREGATEWAYMODE DEFAULT allows both CIP & SCIP (I typically harden this to only accept secure connections, at least from WAN when I'm using SCIP from Crestron Go/App).??

Join [email protected] to automatically receive all group messages.