Please whitelist cPanel in your adblocker so that you’re able to see our version release promotions, thanks!

The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Install SSL without DNS propagating?

Discussion in 'Security' started by rinkleton, Oct 19, 2016.

Tags:
  1. rinkleton

    rinkleton Well-Known Member

    Joined:
    Jul 16, 2015
    Messages:
    61
    Likes Received:
    2
    Trophy Points:
    8
    Location:
    Cleveland
    cPanel Access Level:
    Root Administrator
    Is it possible to install an SSL, preferably autossl, but any other kind could do, before DNS resolves?

    Scenario: We have secure sites we are migrating to another server. It would be great if we could have the SSL all set up when the DNS switchover happens. We can manually do some kind of domain validation like email or a DNS entry. But it looks like WHM does let you install an SSL if the DNS isn't resolved.
     
  2. cPLevey

    cPLevey Technical Analyst Supervisor
    Staff Member

    Joined:
    Dec 3, 2015
    Messages:
    44
    Likes Received:
    8
    Trophy Points:
    83
    Location:
    Houston, TX
    cPanel Access Level:
    Root Administrator
    Hey there!

    cPanel's AutoSSL and SSL certificates from the cPanel Store (Market) require that the domain(s) resolve to a valid IP address for Domain Control Validation checks. However, I noticed in your scenario this is for migrating websites. As long as SSL certificates are installed on the cPanel server the accounts are being migrated from, the Transfer Tool should migrate the SSL certificates with them properly.

    More information regarding the Transfer Tool can be found in our documentation here: Transfer Tool
     
  3. rinkleton

    rinkleton Well-Known Member

    Joined:
    Jul 16, 2015
    Messages:
    61
    Likes Received:
    2
    Trophy Points:
    8
    Location:
    Cleveland
    cPanel Access Level:
    Root Administrator
    After doing a test transfer the cert isn't listed in the store manager or in manage ssl hosts. However I can browse to it. So it seems like it transferred the cert but didn't apply it to the account? It seems like I would have to take some action after the DNS changes. I can test for sure later today.

    Out of curiosity, is it cPanel that is enforcing this Domain Control Validation or is this something out of cPanel's ability to change? The cert in question has already had domain verification done by the issuer, RapidSSL in this case. Just wondering why it needs done again?
     
  4. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    38,659
    Likes Received:
    1,428
    Trophy Points:
    363
    cPanel Access Level:
    Root Administrator
    Hello,

    The domain control validation functionality only applies to the AutoSSL feature. Thus, if you purchased a certificate from RapidSSL, domain validation isn't required. The validation for cPanel-signed certificates is from Comodo. There's a thread here that explains the process:

    cPanel & WHM’s AutoSSL/SSL ordering process

    Let us know if you have any additional questions.

    Thanks!
     
  5. rinkleton

    rinkleton Well-Known Member

    Joined:
    Jul 16, 2015
    Messages:
    61
    Likes Received:
    2
    Trophy Points:
    8
    Location:
    Cleveland
    cPanel Access Level:
    Root Administrator
    Got it. In this case there was something wrong with the root certs on this server not letting it install any SSL. We wiped it and started from scratch and seems to be working as you describe.
     
    cPanelMichael likes this.
Loading...

Share This Page