Disable Http Authentication for cPanel/WebMail/WHM Logins (forces cookie authenticati

ES - George

Well-Known Member
PartnerNOC
Jun 12, 2011
179
25
68
UK
cPanel Access Level
DataCenter Provider
Twitter
Hi,

I can't find the option "Disable Http Authentication for cPanel/WebMail/WHM Logins (forces cookie authentication.)" in Tweak Settings. I've been reading a guide, and it says it's mentioned there.

Also mentioned here.
Security - cPanel Inc.

Any ideas where it is?

Thanks.
 

cPanelTristan

Quality Assurance Analyst
Staff member
Oct 2, 2010
7,607
38
248
somewhere over the rainbow
cPanel Access Level
Root Administrator
Re: Disable Http Authentication for cPanel/WebMail/WHM Logins (forces cookie authenti

In WHM > Tweak Settings, this is now labeled as the following:

Enable HTTP Authentication [?]
Enable HTTP Authentication for cPanel/WebMail/WHM Logins. This risks certain types of XSRF attacks that rely on cached HTTP Auth credentials. Disabling forces cookie authentication.