Skip to main content

SSL for Mailman Admin/User Logins

Comments

7 comments

  • cPanelLauren
    Hi @brianc I'm curious at what point your users are not able to view mailman over a secure connection? If you're using the hostname or a domain with a certificate to access cPanel over https the connection to mailman is also secured, at least in my case 58691
    0
  • brianc
    The problem is not all users particularly list members uses https so there should be some sort of force redirect in place. But the real problem is that for virtual host certificates, some of the form elements do not work properly. I confirmed this on the membership management page when you try to go make some adjustments to a list member settings including adding a real name. It works fine if https is over the hostname of the server but not over the virtual host's certificate.
    0
  • cPanelLauren
    Hi @brianc I still cannot help but feel like something else is going on - I can't replicate any issues with modifying the member names over https with the VirtualHost certificate: 58775
    0
  • brianc
    Hi @brianc I still cannot help but feel like something else is going on - I can't replicate any issues with modifying the member names over https with the VirtualHost certificate: 58775

    I think this appears when you try to disable a non-ssl access to a mailman list. The issues do not show up if I allow both SSL and non-SSL access to a list's admin pages. However when I try to force SSL only access to list admin pages, these issues show up. I believe some of these form elements are using a non-SSL connection to function and when you try to force SSL only access, then something is not working right.
    0
  • brianc
    Hi @brianc It may be that the redirect you're using is causing the issue, but if I access cPanel using the service subdomain as everything including all mailman is viewed over SSL so I'm not sure I understand the need for the redirect to begin with when "require ssl for cPanel services" is enabled even if your users attempt to connect to cPanel non-securely they'll be redirected to SSL.

    Then how come there are non-SSL resources being called when viewing the source html even though the main connection is via SSL? The original need for the redirect is to prevent users from using a non-SSL connection to access Mailman, this includes the list info page. Brian
    0
  • cPanelLauren
    Hi @brianc I have yet to be able to replicate this behavior on my test server (which has a live domain and SSL installed on the domain) and maybe a closer look at the server is warranted. Can you please open a ticket using the link in my signature? Once open please reply with the Ticket ID here so that we can update this thread with the resolution once the ticket is resolved. Thanks!
    0

Please sign in to leave a comment.