Secure Log In

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • jsilver
    Junior Member
    • Sep 2004
    • 26

    #1

    Secure Log In

    I recently had a security audit done and a few concerns came up.

    When logging onto webmail, cpanel or whm, it needs to be through https:. When I do this I get the error that the certificate is invalid or does not match the site issued to. This is because I am accessing https://www.mydomain.com/webmail ... but it is pulling a cert for cpanel28.gzo.com.

    Is there a way to get this to use the cert issued for my domain or have a login screen that does match the gzo cert?

    My security company had this to say:

    Access to webmail system uses a self-signed SSL certificate. Self-signed SSL certificates are used for testing purposes and provde privacy, but absolutely no authentication.

    How can this be resolved?
  • AndrewT
    Administrator
    • Mar 2004
    • 3655

    #2
    To be honest, nothing is going to be changed regarding this. Self-signed certificates are more than sufficient for the basic cPanel/WHM needs and you cannot setup your own for a single domain due to it's limitations. You can always go to http://cpanel28.gzo.com/webmail/ but the certificate is still self-signed.

    Comment

    • jsilver
      Junior Member
      • Sep 2004
      • 26

      #3
      Secure Log in

      Thanks Andrew, that worked. That log in sequence does not prompt the error for the certificate. If I go directly to https://cpanel28.gzo.com:2096/, then it is a secure log in.

      I guess that http://cpanel28.gzo.com:2095/ is my unsecure webmail log in

      and

      https://cpanel28.gzo.com:2096/ is the secure one. Thanks.

      Comment

      Working...