Web Hosting Talk







View Full Version : Security certificate problem with WHM 11?


Frankc22
08-07-2007, 02:40 PM
I am not sure whether it is a bug in WHM version 11 or not but after migrating to a server with WHM 11 on it I got a lot of "This page contains both secure and nonsecure items" warning all over WHM and cpanel.

Already tried anything that I can (perhaps not much) but am still unable to rectify the problem.

Anyone have the same problem?

Regards

MACscr
08-07-2007, 06:36 PM
I am not sure whether it is a bug in WHM version 11 or not but after migrating to a server with WHM 11 on it I got a lot of "This page contains both secure and nonsecure items" warning all over WHM and cpanel.

Already tried anything that I can (perhaps not much) but am still unable to rectify the problem.

Anyone have the same problem?

Regards

Are you using a custom theme?

Frankc22
08-07-2007, 07:14 PM
Yes and no

It is a fresh install on a new server so I used the default X for a while, later migrate to X3 and also installed RVsitebuilder.

Regardless whether I use WHM, Cpanel or RVsitebuilder or whatever theme the message still appears.

I make use of platinumservermanagement.com mainly for security but also asked them to look into the problem. (The response was that they reinstalled the whm certificate but it don't fix the problem)

From my side I reissued all the system certificates via WHM and tried several things without any success. (The certificate name match those in whm and httpd)
ww2.domainname.com

The error don't appear everywhere. Login into whm or cpanel is ok and some admin links too but with for example List Accounts on WHM it always appear. Same apply for cpanel and rvsitebuilder. It only appear on some screens.

MACscr
08-07-2007, 07:22 PM
Are you using the same browser for all of this testing?

Frankc22
08-07-2007, 07:41 PM
I just now tested with Firefox (my normal browser is IE6) and got the same problem.

(The certificate also gave error that the name of the site don't match those of the certificate)

I don't know much about certificates but it seems the two problems are related.

The name of site that don't match the certificate and the secure and non secure items. (The server /host name is ww2.sa-hosting.net and it also appear on the certificate)

https://sa-hosting.net:2083/

ServerManagement
08-08-2007, 12:44 AM
I make use of platinumservermanagement.com mainly for security but also asked them to look into the problem. (The response was that they reinstalled the whm certificate but it don't fix the problem)
hmmmm.... so why not re-open the ticket and tell us directly?

Frankc22
08-08-2007, 01:26 AM
As said I mainly make use of your services for the security related side of the servers and don't want to waste your time with issues like this unless it affect the server performance, operation etc.

(Anyway always try to fix a problem myself before "running" to your guys for help haha. Without training not easy but I learned a hell lot this way)

Will open a ticket if I don't get a solution within next few hours thanks.

Rgs

ServerManagement
08-08-2007, 01:39 AM
don't want to waste your time

I can understand that and appreciate that, but that's what you're paying us for :) Feel free to re-open the ticket and I'm sure we'll be able to fix it up for you.

Frankc22
08-08-2007, 02:28 AM
Your service is great and your pricing too so I want it to stay that way by being at least one customer that put as little pressure on you as possible.

Frankc22
08-08-2007, 03:04 PM
I opened a ticket but only got this meaningless response.

"The ssl for whm has to be accessed at the hostname to avoid errors

Go to https://ww2.sa-hosting.net:2087/ and it will work fine, the only remaining error is that it is not verified and that is because it is a self signed ssl"

The clients cannot access their control panels by hostname while the secure and non secure error message still appears.

Do you ever see a whm installation accessed via IP or domain names displaying such error?

ServerManagement
08-08-2007, 04:45 PM
In our helpdesk, "Client Added Response at 02:59 PM
Problem: Sorry but this answer is meaningless. "

at 03:04 PM, I opened a ticket but only got this meaningless response.

5 minutes between the time you re-opened the ticket and posted your reply on WHT, I guess you just couldn't wait to tell everyone on WHT that our response was meaningless. Well, it wasn't, it was 100% accurate.

If you are asking us for support, then please communicate with us directly. If you are asking WHT for help, then that's fine too. But please keep them separate, I am not going to come to WHT to defend our answers each time you don't like or understand our reply. There is absolutely no need and no benefit involving us or even mentioning us in this thread when you are asking other's for their help.

The ssl installation and answer we gave you from the very beginning is 100% accurate, to clarify exactly what we already told you more in depth:
1) If you go to https://0.0.0.0:2087, the ssl warning will say that the name does not match the ssl, since the ssl is registered to the hostname of the server, and "not" the ip.

There is absolutely no way to avoid this. This is true with any ssl. If you access the ssl at any url other than what it is registered to, the warning WILL say it does not match. That is the entire purpose of the ssl name match warning.

To avoid the ssl name mismatch, you have to go to https://hostname:2087 since the ssl is registered to 'hostname'. That way you will not receive any ssl mismatch error because the name registered in the ssl will match the url you are going to.

We are not saying you can't access whm via the ip or any domain on the server, we are only saying "to avoid the ssl name mismatch error", you must access the ssl exactly the way that the name in the ssl appears.

To simply this, if the ssl is registered to 'blah.com', you must access the ssl at https://blah.com. Any other url like https://ip-of-blah.com, or https://WWW.blah.com will all return ssl name mismatch errors.

2) Since you are using a self signed ssl, you will always get the 'ssl is not verified' error. To avoid this error, you have to buy an ssl from any ssl provider (like geotrust) and we can install it for you.

Again, if you have any other questions or comments, please contact us directly and our techs would've been more than glad to explain this. It is wasting time to have myself AND our tech "both" work on this "same" simple issue in our helpdesk AND on WHT. I appreciate your understanding of this matter.