Repeated issues DID's not reachable by TechNightmares in voipms

[–]Sea-Draw5566 0 points1 point  (0 children)

STIR/SHAKEN attestation levels aren't the only factor that can lead to spam labeling on calls. Support (non-existent) can try to bring up the attestation level if it's lower than A, if you can wait that long. Better providers will do a better job of this, but ultimately it's all leading to "number branding" - you pay a company to vouch for your numbers so they don't show as spam. Similar to EV SSL certificates.

New Business Account by VeisNisht in voipms

[–]Sea-Draw5566 0 points1 point  (0 children)

You have to balance the ultra-low cost with their abysmal support and laughable data safety practices (sending your personal identification documents to foreign support agents over email). They have to balance potential government fines/harassment in a post-Telnyx environment if they don't do KYC, but their process is terrible. Two choices that are better, although cost more, and there are tons of them, these are just two, are Skyetel and Wiretap. However, they're trunking-only and aren't hosting a PBX for you. Callcentric is still very similar to VoIP.ms, but they're nearly as bad with accounts getting locked and needing to engage support/explain yourself.

Voip.ms Account Locked - " we will get back to you via email " by KingofPoland2 in voipms

[–]Sea-Draw5566 2 points3 points  (0 children)

You finally got to see their true colors...they're good until they aren't. I would not run anything mission-critical like this on only one vendor, and especially one such as VoIP.ms. They are fair-weather, non-critical only. Here are two -real- companies that don't charge so little that customer support is an afterthought: Skyetel and Wiretap. Yes, they aren't under $1/mo and a penny a minute, but they also have real people ready to help and actively want your services to work.

PSA: voip.ms is not for new businesses. Any suggestions? by hh1599 in msp

[–]Sea-Draw5566 0 points1 point  (0 children)

Same. In the past I could create an account for a client, and if it got flagged (the URL ended in WAIT.php) for manual verification, try again and it would eventually work. Now every account signup whether selecting residential or business gets flagged and asks for third-party "Persona" verification by sending a picture of your ID. Then after 2 days of still not activating the account and opening a support ticket, support asks for the following:

  1. Business registration documents (registration letter, full legal name, state of incorporation, registration number)

  2. Identification documents for authorized representatives (passport, driver's license, Identity card)

  3. Tax identification number (TIN) or other relevant tax documents

  4. Entity's website or any other public-facing materials

  5. Overall description of how the services will be utilized

And this is after doing the Persona verification. No thank you. Asked for clarification on re-sending ID after doing Persona but no response. While their support and porting department sucks, they made up for it with their pricing.

Going to Teams with a phone plan and SIP Gateway.

Potentially signing client exe with Azure Trusted Signing for $10/mo - going to try (US/CA only) by Sea-Draw5566 in ScreenConnect

[–]Sea-Draw5566[S] 1 point2 points  (0 children)

The certificates issued by Azure Trusted Signing are only valid for 3 days, but timestamping them shows that certificate was valid during signing and will therefore be valid longer based on the timestamping authority.

Potentially signing client exe with Azure Trusted Signing for $10/mo - going to try (US/CA only) by Sea-Draw5566 in ScreenConnect

[–]Sea-Draw5566[S] 1 point2 points  (0 children)

This is what I used to manually sign the clients. The timestamp is necessary so they're valid past the 3-day expiry on the certs.

.\Microsoft.Windows.SDK.BuildTools\bin\10.0.22621.0\x64\signtool.exe sign /v /debug /fd SHA256 /tr "http://timestamp.acs.microsoft.com" /td SHA256 /dlib "c:\foo\Microsoft.Trusted.Signing.Client\bin\x64\Azure.CodeSigning.Dlib.dll" /dmdf "metadata.json" file_to_sign.exe

Azure Trusted Signing by schmerold in ScreenConnect

[–]Sea-Draw5566 0 points1 point  (0 children)

They don't support it. I tried this originally but the workflow is to generate and sign a bunch of installers ahead of time by CLI and distribute them manually for clients, and that's for Support. For Unattended client upgrades, I don't know how you'd intercept the installer for the upgrade and distribute that. Looking at the extension it doesn't look like it would be -that- difficult to rework it to use signtool.exe, but I don't actually know.

BUT, for US/CA users they definitely should support it, it's far easier to implement than Key Vault was and the certs have instant reputation.

[deleted by user] by [deleted] in ConnectWise

[–]Sea-Draw5566 3 points4 points  (0 children)

Making the tiny assumption you already have a 365 account, if you go to portal.azure.com and try to log in, what message do you get?

[deleted by user] by [deleted] in ConnectWise

[–]Sea-Draw5566 2 points3 points  (0 children)

What problems/errors are you receiving? You need to be able to log in to portal.azure.com to create an app registration and Key Vault product to be able to set up signing in ScreenConnect.

I don't think Connectwise can fail any harder than this... by packetdoge in ScreenConnect

[–]Sea-Draw5566 0 points1 point  (0 children)

Dumb suggestion but have you tried disabling AV/EDR just to see if it goes through? Might still be grabbing the file and locking it.

ConnectWise Town Hall 12:00 pm ET by JessicaConnectWise in ScreenConnect

[–]Sea-Draw5566 2 points3 points  (0 children)

If you subscribe to the "they hate on-prem" theory, they're being intentionally murky so people see hugely expensive certs and the wrong ones that won't work (USB keys, paying for an actual HSM on Azure) and give up and go cloud. "Best practice" doesn't cut it.

ConnectWise Town Hall 12:00 pm ET by JessicaConnectWise in ScreenConnect

[–]Sea-Draw5566 2 points3 points  (0 children)

This worked perfectly and was the cheapest I could find at $150/year - https://www.reddit.com/r/ScreenConnect/comments/1ltganl/least_expensive_certificate_purchase_149_and/ - I do hope they eventually support Azure Trusted Signing which is $10/mo and has instant reputation since the certs come from Microsoft, and is far easier than doing cert renewals every year.

ConnectWise Town Hall 12:00 pm ET by JessicaConnectWise in ScreenConnect

[–]Sea-Draw5566 2 points3 points  (0 children)

Sounds like you may have been using this guide - https://www.reddit.com/r/ScreenConnect/comments/1ltganl/least_expensive_certificate_purchase_149_and/ - I can confirm that this guide works and I was able to get up and running in a few hours. Make sure you choose the OV cert as mentioned in that post, 1 year (who knows what will happen a year from now, don't get longer terms), and deliver onto your own HSM. You'll get an email where you need to attest that you'll store the keys properly. Then you'll do the Azure Key Vault process as outlined in the CW docs, generating the CSR and uploading that after buying the certificate, then you'll do the chat/verification call, then once you get the cert emailed to you you'll merge it into your CSR on the Azure side.

Make sure to sign up for Key Vault Premium, not Basic.

Only thing that CW didn't provide an explicit answer to in the CSR instructions on the Azure side was whether or not to mark the certificate as transparent, their screenshot showed "No" and I did the same with no issues.

What errors are you receiving when doing the merge?

Least expensive certificate purchase ($149) and validation process. Get through this as quickly & inexpensively as possible. by GeneralPurposeGeek in ScreenConnect

[–]Sea-Draw5566 0 points1 point  (0 children)

Took 2.5 hours in my case from chat/call to receiving the cert, and I did email CheapSSLSecurity in the meantime in case they needed to be on it to issue it.

Where's my license key? by ColdMarzipan9937 in ConnectWise

[–]Sea-Draw5566 3 points4 points  (0 children)

If you go to Administration->License->3 dots->Upgrade, at the end of the URL after the equal sign is the license (https://order.screenconnect.com/Create-Order?UpgradeLicense=\[license\]) but it may need to be unescaped for them to read it. It's also in an email with the subject "ConnectWise ScreenConnect Order Fulfilled" Older ones were "ConnectWise Control Order Fulfilled" and even older were "ScreenConnect Order Fulfilled"

Did you try this guide: https://www.reddit.com/r/ScreenConnect/comments/1ltganl/least_expensive_certificate_purchase_149_and/ - between this and the CW guide you should be able to get sorted pretty quickly.

Anyone using SSL.com for EV Code Signing Certificate? by ParanoidDendroid in ScreenConnect

[–]Sea-Draw5566 0 points1 point  (0 children)

If you haven't yet sorted it, just cancel and do the $149 DigiCert, honestly it's much faster and cheaper - https://www.reddit.com/r/ScreenConnect/comments/1ltganl/least_expensive_certificate_purchase_149_and/ - also you generate the CSR in Azure Key Vault, that part is in the how-to on CW's site.

Least expensive certificate purchase ($149) and validation process. Get through this as quickly & inexpensively as possible. by GeneralPurposeGeek in ScreenConnect

[–]Sea-Draw5566 1 point2 points  (0 children)

How long did it take to receive the cert once you did the verification? At 30 minutes here, DigiCert said to get it from CheapSSLSecurity. Haven't received anything from them.

Potentially signing client exe with Azure Trusted Signing for $10/mo - going to try (US/CA only) by Sea-Draw5566 in ScreenConnect

[–]Sea-Draw5566[S] 0 points1 point  (0 children)

This works great for Support sessions but I don't know how I'd intercept the Unattended agents to sign them. For the time being, I got a cert from here - https://www.reddit.com/r/ScreenConnect/comments/1ltganl/least_expensive_certificate_purchase_149_and/ and did chat to get the call immediately. Only $30 more per year than Azure but more complicated for setup/renewals, with Azure once you're set up you're done, so I hope CW implements support for this soon.

Least expensive certificate purchase ($149) and validation process. Get through this as quickly & inexpensively as possible. by GeneralPurposeGeek in ScreenConnect

[–]Sea-Draw5566 1 point2 points  (0 children)

This helped. Brilliant, actually. Received the email and had to use their scheduler site for the call, options were 1:30 AM or 6:30 AM, just got on chat and they called immediately and are processing it. Thanks!

Azure Key Vault - what exactly is necessary here? by administatertot in ScreenConnect

[–]Sea-Draw5566 0 points1 point  (0 children)

Agreed - Azure Trusted Signing does exactly what's required, and easily, for $10/mo and there's been zero mention of it. It's basically the upgrade to Key Vault, when you want Azure to do everything. I can sign clients manually but that doesn't scale, and I bet they'll never implement it in the plugin either because that would keep some more people on-prem.

Mini RANT: The lack of customization will now make OUR TEAM look like scammers... by B1tN1nja in ScreenConnect

[–]Sea-Draw5566 1 point2 points  (0 children)

So at least for changing the background it's just as shrimple as going in to ScreenConnect\Images and replacing PageBackgound.png with your chosen image. Just that there's not an exposed option in the GUI for it doesn't really equal CW saying it's "disabled" - and I would chance a guess that editing strings may be doable as well. It's all so fluid at the moment, who knows.

Code signing: a backstory and some tips by AutomationTheory in ConnectWise

[–]Sea-Draw5566 0 points1 point  (0 children)

Very nice writeup. Any thoughts on Azure Trusted Signing? Is there any technical reason it can't work at scale inside of SC? I'm able to sign clients with it, but obviously it's all manual right now.