Skip to main content

Addon domains and DNS record verification

Comments

4 comments

  • cPanelLauren
    Hi @sparek-3 It sounds like (and please correct me if I misunderstood what you're asking) you just need to change some tweak settings. Specifically, the following two: [QUOTE] Allow Remote Domains Allow creation of parked/addon domains that resolve to other servers (e.g. domain transfers) This can be a major security problem. If you must have it enabled, be sure not to allow users to park common Internet domains.
    [QUOTE] Allow unregistered domains Allow creation of parked/addon domains that are not registered.
    0
  • sparek-3
    Apologies for not being too clear. That's true, those configuration options would work. But it's generally accepted to leave those options enabled. I agree with the reasons for leaving them enabled. The issue pops up once in a blue moon, so I guess it's not entirely out of the realm to temporarily disable it and re-enable it once the client with this addon domain adds the domain. But doing this also completely circumvents the entire purpose of those configuration options, who's to say that the client isn't trying to take advantage of a lesser known, but specific to their needs, domain name hijacking? It just doesn't seem like an eloquent solution. Perhaps a TXT record verification process could be implemented. Say the user has one of these domain names that gets caught in this catch-22. The addon domain interface could create a token and a DNS TXT record instructing the user to create the TXT record and check back once it has been added to verify domain registration ownership. Or is the issue just not common enough to warrant spending any time on? Seeing as how this thread has not gotten any other responses... perhaps I'm operating as an army of one.
    0
  • ronaldst
    I've had a few of these occour as well. I decided to add the domains manually from WHM (with root privileges, obviously). At the time being I considered this to be the best option, and disabling the tweaks the least favourable one for obvious reasons.
    0
  • cPanelLauren
    But doing this also completely circumvents the entire purpose of those configuration options, who's to say that the client isn't trying to take advantage of a lesser known, but specific to their needs, domain name hijacking?

    You really don't unless you're aware of what the client is adding/doing which would be why there's no real automatic solution here besides utilizing the settings in place to suit your needs. The tweak settings can be enabled/disabled at will - so if you need to enable it to allow for a user to create a domain you can do so until the domain is added then disable it once more. This can even be done after the domain is added and still doesn't point to the server or isn't registered.
    addon domain interface could create a token and a DNS TXT record instructing the user to create the TXT record and check back once it has been added to verify domain registration ownership.

    If the issue is the necessity for a TXT or some other type of record the root WHM user has the ability to modify the DNS zone files, as well as add them for domains that don't exist on the server. In most cases, the cPanel user will have the capability to manage existing DNS zones as well in the Zone Editor unless it's not a part of the package applied to their account. I actually think it's a really good thing to have the server admin involved in the ability to add these, I'm not sure I would be on board with a solution that would just let folks automatically add these domains unless it was comprehensive.
    0

Please sign in to leave a comment.