Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

standard cPanel service URLs on http:// do not redirect to https:// when compared to without nginx - PCI compliance issue #1487

Open
pgrandmaison opened this issue Jun 13, 2024 · 1 comment

Comments

@pgrandmaison
Copy link

Hi,
I just noticed that on servers that do not have Engintron, going to http://webmail.domain.tld on cPanel auto-redirects to https://webmail.domain.tld when the appropriate settings are configured in WHM--> Tweak Settings:

Choose the closest matched domain for which that the system has a valid certificate when redirecting from non-SSL to SSL URLs. Formerly known as “Always redirect to SSL/TLS” [ENABLED]

Require SSL for cPanel Services --> ON

On this cPanel without Engintron, going to http://webmail.domain.tld , it automatically redirects to https://webmail.domain.tld which has a valid SSL installed.

On the same cPanel with Engintrol installed, going to http://webmail.domain.tld does not redirect to https://.

I believe this is a bug, and it will affect PCI compliance on future PCI compliance scans.

@pgrandmaison
Copy link
Author

I actually just came across this documentation post:
https://engintron.com/docs/#/pages/Redirect-webmail.domain.tld-from-HTTP-to-HTTPS

Looks like this is exactly what I need. I'm wondering why we don't include this by default?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant