store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Sun May 19, 2013 9:44 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 3 posts ] 
Author Message
 Post subject: T-WAF with Plesk - unable to upload SSL certificate/CA
Unread postPosted: Sun Aug 19, 2012 10:29 am 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1843
I've just discovered that with the T-WAF enabled for Plesk, attempting to set/modify an SSL certificate via admin->SSL Certificates fails with a "Forbidden - access denied for /plesk/certificate[*]/"

Basically, although it is possible to create a new certificate (Private key & CSR), it is then not possible to upload or paste the actual certificate and CA for it.

Disabling the T-WAF in the ASL gui, waiting 60 seconds or so for it to get really disabled (you'll have to login to Plesk again) resolves the problem - it is then possible to upload or paste the certificate and CA again.

I'm not seeing any errors in the GUI log (even down to level 2), nor in the Plesk admin error log.

NOTE: If, like me, you have also disabled Filemanager (/usr/local/psa/admin/[s]bin/filemngr) you will also have to re-enable it - it seems as though it gets used for actual admin stuff as well as for customer file management.

I've duplicated this issue on two systems, so it isn't a one off. Both are Plesk 10.4.4 MU40 with Centos 6 64-bit and asl-waf-module-3.0.32-1.el6.art.x86_64 and asl-3.0.32-1.el6.art.x86_64

Can someone else who has the T-WAF enabled please have a go to confirm my findings? You just need to create a bogus certificate (e.g. www.test.tld) in the admin panel, then try to upload any old certificate and CA for it. It should fail with a Forbidden message.

I have NOT tested to see if the same issue applies to uploading certificates/CAs for individual domains (i.e. subscription/domain->control panel->ssl sertificate)

Thanks,

Faris.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
 Post subject: Re: T-WAF with Plesk - unable to upload SSL certificate/CA
Unread postPosted: Mon Aug 20, 2012 12:30 pm 
Offline
Forum Regular
Forum Regular

Joined: Wed Jan 02, 2008 3:21 pm
Posts: 515
Location: United Kingdom
Recently contacted ASL support with this same issue.
Apparently it is a known bug, something to do with the # in the URL.


Top
 Profile  
 
 Post subject: Re: T-WAF with Plesk - unable to upload SSL certificate/CA
Unread postPosted: Mon Aug 20, 2012 4:56 pm 
Offline
Long Time Forum Regular
Long Time Forum Regular

Joined: Thu Dec 09, 2004 11:19 am
Posts: 1843
Thanks KM.

_________________
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 3 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group