Secure admin panel

  • Ok, this default page could make sense.
    I don´t see there "more" security by redirect the Login to a other page.


    It is no problem to collect some quick infos about a server an the panel.:rolleyes:


  • I don´t see there "more" security by redirect the Login to a other page.


    I agree, not really a security bit. Although it could stop some browser SSL name mismatch errors. i.e. what would happen if control panel ssl cert has a Common Name of "admin.slashdot.org" and it gets loaded via url "https://80.80.80.80/" instead of the admin https url.

  • I agree, not really a security bit. Although it could stop some browser SSL name mismatch errors. i.e. what would happen if control panel ssl cert has a Common Name of "admin.slashdot.org" and it gets loaded via url "https://80.80.80.80/" instead of the admin https url.


    The errors will still be there, even if you only use the https to do a redirection to somewhere else the certificate has to be valid (AFAIK)
    Even all the discussion the idea of having a catchall 'welcome' page is not that bad, from security point of view doesn't have much importance, but for customer that are wandering around could be nice.

  • I have updated my howto (should work/want test it). Can someone tell me how I can create via command the new config files?

    Edited once, last by mafioso ().

  • tha apache config files in /etc/apache2/sites-enabled/
    this files were generated with the template files in /etc/imscp/apache/* via i-mscp...
    In my howto I have edited the template files and want to generate now the new config files..

  • Not sure if the old ispCP way still works but you can try it.
    Set the domains in the db to "change" an run the imscp-rqst-mngr.


    As i said - dont know if this works. The new setup does it also.


    Greez BeNe

  • how can I run the imscp-rqst-mngr.?
    Also is there another simpler way? But I'll try it, thanks :)