Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

SOLVED Auto SSL DCV Validation error Bug on Apache Custom Port

Discussion in 'Security' started by syslint, Jan 12, 2018.

Tags:
  1. syslint

    syslint Well-Known Member

    Joined:
    Oct 9, 2006
    Messages:
    262
    Likes Received:
    6
    Trophy Points:
    168
    Location:
    India
    cPanel Access Level:
    Root Administrator
    Twitter:
    There is an issue with apache DCV validation while apache runs on a custom port. This may result in accessing the DCV temporary files via proxy from another webserver in port 80

    Steps to Recreate the issue:

    1) Access the key webdisk.example.com/.well-known/pki-validation/DE86811B0380F9DFF632716F443CF18D.txt via apache on port 80 works fine without redirection to ssl port
    2) Change apache port to some other port say 9080 , then webdisk.example.com:9080/.well-known/pki-validation/DE86811B0380F9DFF632716F443CF18D.txt, won't work. It always redirect to HTTPS.

    For updating the correct Autossl certificate those subdomain urls must be need to be working in HTTP instead of HTTPS even with custom port change in apache. This issue exist in all versions of cpanel.
     
    #1 syslint, Jan 12, 2018
    Last edited by a moderator: Jan 13, 2018
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    41,516
    Likes Received:
    1,616
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Hi @syslint,

    I just wanted to follow up to let you know we do have an additional internal case open to determine if it's feasible for AutoSSL to properly detect the custom Apache port. I'll update this thread with more information on the status of this case as it becomes available.

    Thank you.
     
  3. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    41,516
    Likes Received:
    1,616
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Hello,

    To update, internal case CPANEL-18074 will allow for AutoSSL DCV with proxy subdomains when using a custom Apache (non-SSL) port. I'll update this thread again once it's published.

    Thank you.
     
  4. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    41,516
    Likes Received:
    1,616
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Hello,

    Internal case CPANEL-18074 is now published as part of cPanel version 70:

    Fixed case CPANEL-18074: Allow proxy subdomain HTTP DCV to work over nonstandard non-SSL port.

    There's an open request to backport this to cPanel version 68 as well. I'll update this thread with more information on the status of the backport as it becomes available.

    Thank you.
     
    Jose Nobile likes this.
  5. Jose Nobile

    Jose Nobile Member

    Joined:
    Jun 5, 2015
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    1
    Location:
    Cali, Colombia
    cPanel Access Level:
    Root Administrator
    Posting this only to receive a notification when it is backported to the current cPanel version. Is there another way to subscribe to notifications?
     
  6. Infopro

    Infopro cPanel Sr. Product Evangelist
    Staff Member

    Joined:
    May 20, 2003
    Messages:
    16,009
    Likes Received:
    341
    Trophy Points:
    433
    Location:
    Pennsylvania
    cPanel Access Level:
    Root Administrator
    Twitter:
    Top right corner of this thread is a link to "Watch Thread".
     
  7. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    41,516
    Likes Received:
    1,616
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Hello,

    You can also follow the cPanel 68 Change log at:

    68 Change Log - Change Logs - cPanel Documentation

    Keep in mind cPanel version 68 isn't a LTS (Long Term Support) version, so it becomes end-of-life once cPanel version 70 reaches Stable. cPanel version 70 is tentatively planned for publication to the "Current" build tier this week.

    Thank you.
     
  8. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    41,516
    Likes Received:
    1,616
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Hello,

    To update, internal case CPANEL-18074 is now published to cPanel version 68.0.29:

    Fixed case CPANEL-18074: Allow proxy subdomain HTTP DCV to work over nonstandard non-SSL port.

    Thank you.
     
Loading...

Share This Page