Plesk 12.x / Linux :: Turn Off SSLv2 And SSLv3 Protocols On All Domains On Server
Oct 16, 2014Trying to turning off SSLv2 and SSLv3 protocols on all domains on a Plesk 12 CentOS 6 virtual server.
View 7 RepliesTrying to turning off SSLv2 and SSLv3 protocols on all domains on a Plesk 12 CentOS 6 virtual server.
View 7 RepliesWe have tested one of our CentOS 6.6 Plesk 12 servers to see if it was vulnerable to the poodle attack using the poodle.sh script from [URL] .... and found it was.
Then downloaded the special script from the same article run the script and re tested and everything was no longer vulnerable. But then started getting complaints from customers that they could not send email anymore and looking at it found errors like:
qmail: 1436280789.522657 delivery 768: deferral: TLS_connect_failed:_error:14082174:SSL_routines:SSL3_CHECK_CERT_AND_ALGORITHM:dh_key_too_small;_connected_to
After looking in the forum found an extended cyphers list, which when used starts to allow email to be sent as normal. But then checking with the vulnerability script agian find that it has also allowed connections to ports 587 and 465 agian via SSL3v
Webmail used is Roundcube and Horde.
how to use Plesk through “Customer's Guide, Plesk 12.0” manual from Odin website. I have a VPS Cloud plan at OVH with Plesk 12 Web Admin + CentOS 6.6
I wish to know how to enable POP3, IMAP, SMTP, FTP protocols with a cryptid connections using native Plesk/CentOS certificate (not purchasing one but self-made by the server). Moreover, I wish to know if it uses SSL or TLS.
I want to reject all email traffic from the internet except those as below can send mail to my Plesk server :
+ my antispam ( smarthost ) with IP ( a.b.c.d )
+ all my user in the plesk server with authentication
So i plan to set SPF checking on to Reject mail if SPF does not resolve to pass but
1. can't find option to whitelist my smarthost IP Is that option Local Rule: " v=spf1 ip4=a.b.c.d -all "
2. all of my user do not affected by the "Reject mail if SPF does not resolve to pass " right ?
an email notification for this is coming through every day. It says ended successfully so no errors...
Running task: C:Pleskadmininweb_statistics_executor.exe
Started: Fri Jun 19 01:49:01 2015
Ended successfully: Fri Jun 19 01:49:09 2015
If i go to Server -> Scheduled Tasks and look for it, it cannot be found anywhere. Also scheduled tasks only shows system users, not 'Plesk Administrator' as the kb articles refer to.
I need to transfer all of my domains to a new server is there an easy solution to avoid manually backing up all the files, databases create new subscriptions,domains etc Also i will have to perform the same task for a local development machine which has already plesk 12 install (debian 7.8)
So in summary Plesk 11.5 (centOs 5.6) => Plesk 12 (debian 7.8)
Simple... new Plesk 12 includes this fancy feature to tell me which Wordpress plugins and themes need updating (because I obviously can't do this myself). But maybe I don't want to update some plugins (because they've been customized and changed)... how do I....
STOP Plesk 12 from sending me Wordpress update notification emails EVERY DAY!???? The auto-update is off... and EVERY day is sends me (and all of those clients) an ugly email about their Wordpress installations. How do I turn this OFF?
I created a New Client Default Domain by copying plesk's original Default Domain.This template is for clients we move from older versions of plesk up to servers with plesk 12.x. Under resources for that "Service Plan Name"
I have Sites published with Presence Builder set to 0 and.Allow customer to create trial Presence Builder websites. Not checked.When I log in as the client I still see Presence Builder with edit Website.I also confirmed the correct plan was picked for that subscription by picking the new "New Client Default Domain" and under add-on plans I picked "remove"
But when I log in as the "client" to see what they would see I see Presence Builder and Edit Website available.How do I get rid of that selection?I can see a client clicking on it and basically over writing their current website.
How do I turn off prompt to update application vault apps?
View 10 Replies View RelatedI've got a serious problem with a domain I purchased from parallels marketplace.
I have a plesk installation at my current provider (server4you.de) and I ordered a domain via the integrated services of plesk: marketplace.parallels.com
Great. So now I own the domain.
However, I cannot propagate my IP or set the domain's dns servers. Of course, a proper DNS template has already been applied.
My plesk installation is not hosted by parallels. My provider (server4you.de) sais, they can't do anything, because I ordered via plesk panel. The domain has been purchased via marketplace.parallels.com, but the registrar is tucows. I have no user account for tucows. Regardless what the plesk KB sais, it is NOT possible on my marketplace account to set the nameservers. I don't have that option in my marketplace account.
It seems like I have a domain now that I cannot use. Where can I set the nameservers for the domain?
The parallels support is hidden behind seemingly 1000 barriers. Whom can I contact to set the nameservers for me? I CANNOT even transfer the domain to my provider as the domain status is "server transfer prohibited".
I've checked the firewall and FTP is allowed incoming, I added the passive ports to the firewall. Plesk shows the user in active connections, but when I connect to any domain I get an error that its not able to retrieve the directory. I am not sure if plesk just doesn't know what the directory is or if the main config messed up on the domain or sites level. I am running Plesk 12 on CentOS7.
View 1 Replies View RelatedI understand it is not possible to move a domain to another subscription, or to create a new subscription with an existing domain name.The problem I have is I wish to use a different IP address for a domain within a single subscription. I need to do this to establish SSL cert on one of the domains.
View 1 Replies View RelatedI have multiple domains on a single IP address and many require SSL Certificates.
I have enabled SNI in /etc/psa/psa.conf so it now says "SNI_SUPPORT true" as it was originally set to False. Setting this to TRUE then enabled the SSL option in 'Websites & Domains'.
I then purchased and installed the SSL Cert and activated it in the domain settings. On a dedicated IP address, this would work.
When I checked the certificate. it was not using the assigned SSL cert, instead it was using the Servers default certificate (plesk) that is assigned to the shared IP address.
When I check, I get the error message: "[warn] RSA server certificate CommonName (CN) `plesk' does NOT match server name"
I then rebooted the server and it made no difference. I changed the domain to a spare dedicated IP address, and the SSL Cert was certified correctly (it used the correct SSL Cert). When I changed it back to the shared IP address, it reverted back to the shared IP address' SSL cert. So the new SSL Cert was being ignored.
For info: currently running 11.0.9 on Centos 5 and I'm testing this with latest IE, FF, Chrome so it accepts TLS Server Name Indication.
I run a VPS with Plesk 12. Can I set SSL certificates for all the domains on this VPS?
I don't need to know how to do it (yet). I'm just wondering if it is possible.
(I have 2 IP addresses to my VPS. I was told the second one was for SSL, but I'm not sure if I need it?)
A load of my domains were backed up last night and they have been suspended ever since. I have tried the following:
1. Domains -> Backup Manager -> Back Up
2. tick off the box to the left of "Suspend domain until backup task is completed"
3. Tick off the box to the left of "Domain configuration"
4. Click "Back Up".
...That did not fix it
I've tried suspending/activating the domains, but I just receive "Error: Unable to activate the domain: The domain is suspended."
I've also logged into MySQL PSA database and run "update domainaliases set status=0 where status=2;" ...That did not fix it
I have checked and /var/www/vhosts/domain.com/conf/httpd.include file is missing.
I have also run the following command: /usr/local/psa/admin/sbin/httpdmng --reconfigure-all
That did not fix it
if I try "/usr/local/psa/bin/domain -u mydomain.com -status enabled" I receive the following error message...
An error occurred during domain update: Turn on domain failed: /usr/share/tomcat5/conf/server.xml:1451: parser error : Extra content at the end of the document vice>
tomcatmng: Unable to parse tomcat server config /usr/share/tomcat5/conf/server.xml
I'm on the latest 11.0.9 Update #63
Impossible to find a way to show, by default, all domains and websites...
When I log on the Plesk Admin, I come first on a list of websites and domains, but they are not «all» listed. I have to go to the full bottom of the page to click on «Show all».
I didn't find a preference or anything else to change that, and I don't understand why all domains are not listed.
We have a domain with two domains aliases.
How can we have certificate with each domains ?
since yesterday I'm receiving this errors on some website: see attachment
View 2 Replies View RelatedI would like my clients only to be able to access Plesk Panels from a certain domain, instead all from or with all the domains hosted on our server, is there a way to accomplish that?
View 1 Replies View RelatedI have installed the nginx on my server and want to activate it for all my domains, to do this, i have to do it manually for each domains. But there should be an easier way. Apache uses too much ram.
View 7 Replies View RelatedI have a virtual server linux with Strato. When I have upgrade from 11.5 to 12.0.18 in spanish I have seen that I can´t add a new domain in power user. The user has ilimited domains and I have less that 10 domains. I see the buttom of "add domain" as in 11.5 and appears all the fields to complete, but there is not buttom to accept o decline. There is no problem with alias or subdomain. I have reinstall 11.5 and dissapeared the problem, but when I upgrade again to 12.0 this buttom doesn´t appear.
View 1 Replies View RelatedUnfortunately today the mailboxes of two domains were "gone". The mailbox was still there physically but no mails would be delivered into the mailbox, nor could the user connect to it.
The log said:
Apr 20 07:22:11 plesk dovecot_authdb_plesk[30678]: No such user 'mail@domain.com' in mail authorization database
Apr 20 07:22:11 plesk dovecot: auth: Debug: master in: USER#0111#011mail@domain.com#011service=lda
Apr 20 07:22:11 plesk dovecot: auth: plesk(mail@domain.com): Mail account information for user='mail@domain.com' was not found
Apr 20 07:22:11 plesk dovecot: auth: Debug: userdb out: NOTFOUND#0111
Apr 20 07:22:11 plesk postfix/pipe[27105]: 7DD5F5DA02D: to=<mail@domain.com>, relay=plesk_virtual, delay=90585, delays=90585/0/0/0.03, dsn=4.2.1, status=deferred (Message can not be delivered at this tim$
The only solution that worked for me was to delete the mailbox, create it again and copy the old mails back. That problem only occured in two cases (two domains of one customer). All his other domains worked like a charm and no other customer was affected.
I have a server which I am using for multiple clients. Some with SSL enabled, some without. I have added custom ngingx conf files for nginxDomainVirtualHost.php and nginxWebmailPartial.php in /usr/local/psa/admin/conf/templates/custom and modified the following lines to try and harden security:
Code:
ssl_protocols TLSv1 TLSv1.1 TLSv1.2;
ssl_ciphers "EECDH+ECDSA+AESGCM EECDH+aRSA+AESGCM EECDH+ECDSA+SHA384 EECDH+ECDSA+SHA256 EECDH+aRSA+SHA384 EECDH+aRSA+SHA256 EECDH+aRSA+RC4 EECDH EDH+aRSA RC4 !aNULL !eNULL !LOW !3DES !MD5 !EXP !PSK !SRP !DSS";
ssl_prefer_server_ciphers on;
After reconfiguring using
Code:
/usr/local/psa/admin/bin/httpdmng --reconfigure-all
I check in /etc/nginx/plesk.conf.d/vhosts/<domain>.conf and the changes are shown correctly there but browsers and online tools such as [URL] .... still say that the sites are using 128 bit encryption and TLS 1.0.
The Plesk admin panel itself displays 256 bit encryption and TLS 1.2.
When I log into plesk (service provider view) and click on the Domains link on the left, I get an empty page. It isn't blank like there is an error, it has some instructions at the top about creating a customer etc. It just doesn't list any of the domains that are setup on the server. There are several reseller accounts with several domains under each. I've even tried setting up a new customer and adding a domain under the new customer. Still nothing shows up.
I have several other VPS accounts running Plesk 12 with several domains under different customer accounts and the domains all show up on those.
I just upgrated from Plesk 11 to Plesk 12 and now it looks like my admin account is not admin anymore. I can only see the domains that is subscribed to my username.
Is that normal? How can I see all subscriptions now?
Some sites reach maximum children
so I need to change
pm.max_children = 5
for all new domains on a server
How can this be done?
I know i can change it manually on each new domain, is there some kind of template to modify?
I have 12 domains in my control panel but i only see 5 domains in my control panel but all 12 domains are working they are up but only see 5 in control panel....
View 7 Replies View RelatedSystem: Plesk Panel 12, updated on CentOS 6
Situation:
"Main-domain" domain with 2 "alias-domains" (301-forward). For "Main-domain" I created a wildcard subdomain. All works fine.
ToDo:
I want to create wildcard domains for both "alias-domains".
Problem:
It is not possible to create wildcard subdomains for both "alias-domains".
1. How to create wildcard-subdomains on "alias-domains"?
2. How do I disable Plesk to respond to every domain, which isnt covered by a wildcard?
I have setup a new CentOS 6.6 server with Plesk version 12.0.18 and everything works as it should apart from the fact that in Filezilla the connection for domain1.com points to the httpdocs directory for domain2.com and vice versa. In the plesk filemanager and in a web browser the domains point to the right directory.
View 4 Replies View RelatedCan't add new subscriptions or domains/ subdomain after upgrade. Upgraded to 12.0.18 today and can no longer add domains or subdomains. When I try create a new subscription I get the following error:
New configuration files for the Apache web server were not created due to the errors in configuration templates:
Template processing failed: file = /usr/local/psa/admin/conf/templates/default/domainVhost.php, error =
Template_Exception: No data. file: /usr/local/psa/admin/plib/Template/Processor.php line: 28 code: 0 Previous error: Template_Variable_Exception: No data. file: /usr/local/psa/admin/plib/Template/Variable/AbstractCachedData.php line: 67 code: 0.
Detailed error descriptions were sent to you by email. Please resolve the issues and click here to generate broken configuration files once again or here to generate all configuration files.
Trying to generate all configuration files OR generate broken configuration files doesnt work. Still get the same error.
When I try can create a subdomain I get the error:
.............
Error: proftpd-config failed: mktemp: failed to create file via template `/etc/proftpd.d/50-plesk.conf.XXXXXX': No such file or directory
Can not create temporary file
...........
This solution [URL] ..... doesnt work that just says 'ls: cannot access /etc/proftpd.d/: No such file or directory'
I tried yum update proftpd to see if that would do anything but get this...
Loaded plugins: fastestmirror, priorities
Loading mirror speeds from cached hostfile
* atomic: mir01.syntis.net
193 packages excluded due to repository priority protections
Setting up Update Process
No Match for argument: proftpd
No package proftpd available.
No Packages marked for Update
In plesk, ProFTPD ftpserver is showing as installed.