Can FusionPBX Support Intra-PBX E2EE Calls Between PBX Extensions Using VOIP Clients?

Status
Not open for further replies.

dogmaster

New Member
Jun 30, 2022
2
0
1
24
Currently running a small, six-extension FreePBX on a VPS where all extensions use LinPhone Laptop or LinPhone Android VOIP clients.

We'd originally selected and deployed on FusionPBX but a VOIP contractor convinced us that E2EE and other features we sought would be more readily deployed and/or implemented on FreePBX.

For a variety of reasons other than E2EE we're considering migrating back to FusionPBX but would like to know whether Intra-PBX E2EE calling is in fact a bridge too far.

We'd thought this problem solved at one point when both clients indicated their calls were encrypted, but quickly determined from PBX call recordings that the calls were only encrypted between the PBX and LinPhone clients, and that the PBX was literally acting like a MITM of the call stream. True E2EE would seem to require that extension clients negotiate between themselves their call-specific E2EE keys via ZRTP and to somehow notice the PBX to not interfere.

After polling numerous VOIP vendors, contractors, forums, etc. to-date we've not found a single organization or person that's implemented Intra-PBX E2EE calling with any VOIP client, much less LinPhone - our preferred VOIP client.

Has anyone actually gotten Intra-PBX E2EE calling to work with FusionPBX?

Or are we hunting a unicorn?
 

hfoster

Active Member
Jan 28, 2019
682
81
28
34
I don't think it's a unicorn as such, FreeSWITCH has all the tools necessary, that MITM thing you described, I think is the setting zrtp_enrollment which can be disabled afaik. Really not an expert in it though.

Personally, I get as far as encrypting the tunnel that phones use and call it a day. After all, it's all plain-text as soon as it hits the PSTN.
 

dogmaster

New Member
Jun 30, 2022
2
0
1
24
I don't think it's a unicorn as such, FreeSWITCH has all the tools necessary, that MITM thing you described, I think is the setting zrtp_enrollment which can be disabled afaik. Really not an expert in it though.

Personally, I get as far as encrypting the tunnel that phones use and call it a day. After all, it's all plain-text as soon as it hits the PSTN.
Yes, I understand it's a technical impossibility for a 'vanilla' PSTN phones to ever encrypt or decrypt traffic.
But by intra-PBX calling I meant calls that originate and end at PBX extensions using ZRTP-compatible, encryption-capable softphones.
 
Status
Not open for further replies.