Skip to main content

Add TLS version and cipher to cPanel logs

Comments

3 comments

  • cPanelLauren
    Hi @sparek-3 That's a great idea but it's not possible to make modifications to the cPanel access_logs in the same manner due to the fact the data for that is hardcoded in our binaries. I think it'd be a really useful feature request though. I'd say use the link in my signature to open a feature request then let us know the link so we can all vote on it too. Thanks!
    0
  • sparek-3
    Would probably lose it's luster before it gets through the requisite feature request bureaucracy. The main point would be to identify those users that are still using browsers/OSs that rely on TLSv1 and TLSv1.1 (and there's a ton of them) before the recommended PCI deadline of June 30, 2018 (oops! that's already passed ... yes, I'm being sarcastic at everyone's viewpoint toward security recommendations). I'll just modify the Apache combined log to show this and have users visit a dummy Apache served page to see what TLS version they are using. Seems simpler this way.
    0
  • cPanelLauren
    I understand, if you do decide to open it for some reason, please let us know. Thanks!
    0

Please sign in to leave a comment.