SOLVED Auto SSL DCV Validation error Bug on Apache Custom Port

syslint

Well-Known Member
Verifed Vendor
Oct 9, 2006
268
7
168
India
cPanel Access Level
Root Administrator
Twitter
There is an issue with apache DCV validation while apache runs on a custom port. This may result in accessing the DCV temporary files via proxy from another webserver in port 80

Steps to Recreate the issue:

1) Access the key webdisk.example.com/.well-known/pki-validation/DE86811B0380F9DFF632716F443CF18D.txt via apache on port 80 works fine without redirection to ssl port
2) Change apache port to some other port say 9080 , then webdisk.example.com:9080/.well-known/pki-validation/DE86811B0380F9DFF632716F443CF18D.txt, won't work. It always redirect to HTTPS.

For updating the correct Autossl certificate those subdomain urls must be need to be working in HTTP instead of HTTPS even with custom port change in apache. This issue exist in all versions of cpanel.
 
Last edited by a moderator:

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,910
2,215
363
Hi @syslint,

I just wanted to follow up to let you know we do have an additional internal case open to determine if it's feasible for AutoSSL to properly detect the custom Apache port. I'll update this thread with more information on the status of this case as it becomes available.

Thank you.
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,910
2,215
363
Hello,

To update, internal case CPANEL-18074 will allow for AutoSSL DCV with proxy subdomains when using a custom Apache (non-SSL) port. I'll update this thread again once it's published.

Thank you.
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,910
2,215
363
Hello,

Internal case CPANEL-18074 is now published as part of cPanel version 70:

Fixed case CPANEL-18074: Allow proxy subdomain HTTP DCV to work over nonstandard non-SSL port.

There's an open request to backport this to cPanel version 68 as well. I'll update this thread with more information on the status of the backport as it becomes available.

Thank you.
 
  • Like
Reactions: Jose Nobile

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,910
2,215
363
Hello,

You can also follow the cPanel 68 Change log at:

68 Change Log - Change Logs - cPanel Documentation

Keep in mind cPanel version 68 isn't a LTS (Long Term Support) version, so it becomes end-of-life once cPanel version 70 reaches Stable. cPanel version 70 is tentatively planned for publication to the "Current" build tier this week.

Thank you.
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,910
2,215
363
Hello,

To update, internal case CPANEL-18074 is now published to cPanel version 68.0.29:

Fixed case CPANEL-18074: Allow proxy subdomain HTTP DCV to work over nonstandard non-SSL port.

Thank you.