The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

AutoSSL and Password Protection

Discussion in 'Security' started by PenguinInternet, Sep 3, 2016.

Tags:
  1. PenguinInternet

    PenguinInternet Well-Known Member
    PartnerNOC

    Joined:
    Jun 20, 2007
    Messages:
    149
    Likes Received:
    1
    Trophy Points:
    18
    Location:
    Cardiff, UK
    cPanel Access Level:
    DataCenter Provider
    Twitter:
    I've seen the same issue present when a site is .htaccess password protected - this stops validation as the file cannot be accessed and so is one scenario to consider
     
  2. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,854
    Likes Received:
    675
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    Hello @PenguinInternet,

    I've moved this post to it's own thread. I'm not sure that temporarily excluding a file name from the password protection feature is a good option from a security perspective. What are your thoughts on that? Note that you can find further discussion of this topic, and a workaround to this issue at:

    AutoSSL - htaccess whitelist

    Thank you.
     
  3. monarobase

    monarobase Well-Known Member

    Joined:
    Jan 26, 2010
    Messages:
    503
    Likes Received:
    0
    Trophy Points:
    16
    Location:
    France
    cPanel Access Level:
    Root Administrator
    What about simply moving the application to a new folder like, /public_html/secure/ instead of just /public_html and adding a wildcard redirect excluding lets encrypt/comodo verifications. This won't work for everyone but might help in some cases.
     
  4. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,854
    Likes Received:
    675
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    This might work as a user-submitted workaround in some cases, but moving a directory could open up the potential for additional problems if something goes wrong (e.g. the server stops responding in the middle of the move).

    Thank you.
     
Loading...

Share This Page