Skip to main content

CPANEL-42630 - Determining best certificate logic

Comments

4 comments

  • sparek-3
    I think the issue may be that the addon domain's (i.e. [font="courier new">addondomain.com) certificate is expired... but there is a mail subdomain attached to that addon domain ([font="courier new">mail.addondomain.com) that is valid. It would seem that the system is not adding [font="courier new">mail.addondomain.com to the list of domains to check for a valid certificate. Seemingly the steps to duplicate this would be to add an addon domain ([font="courier new">addondomain.com) to an account Don't issue a CA signed certificate for this addon domain. Create a mail. subdomain for this domain ([font="courier new">mail.addondomain.com) Issue a CA signed certificate for this mail. subdomain ([font="courier new">mail.addondomain.com) and just for this subdomain. Create an email account on the addon domain ([font="courier new">[plain]test@addondomain.com[/plain]) Click the Connected Devices button on the Email Accounts list page for this newly created email account ([font="courier new">[plain]test@addondomain.com[/plain]) Note that the Secure SSL/TLS Settings (Recommended) does not list mail. subdomain ([font="courier new">mail.addondomain.com) as the recommended incoming and outgoing mail server to use.
    0
  • cPRex Jurassic Moderator
    Hey there! I think the main issue here is that cPanel isn't designed to support only the mail subdomain in the certificate. In a default addon domain scenario, at least on my test server with live DNS, both the domain and mail.domain.com were secured with the SSL. When I follow these instructions with the default SSL, the correct settings are shown in both a mail client (I used Thunderbird for testing) and cPanel >> Connect Devices: -created an addon domain -configured DNS for the domain -ran AutoSSL to ensure the domain/subdomain was secured -confirm the domain could be reached over https in a browser, indicating the SSL has been applied Can you get me more details on why the mail subdomain would have an SSL but the main domain wouldn't? I'm happy to create a case with the developers about the cert for just "mail" not being enough to be detected properly, but I'd like to have a bit more background and how we got to this scenario, if possible.
    0
  • sparek-3
    What if we're only handling mail for [font="courier new">addondomain.com? What if [font="courier new">addondomain.com and [font="courier new">[plain]www.addondomain.com[/plain] are resolving to some other remote server. [font="courier new">mail.addondomain.com is resolving to our server. And the MX record for [font="courier new">addondomain.com is pointing to [font="courier new">mail.addondomain.com Additionally, what if [font="courier new">mail.addondomain.com has a paid certificate? There really shouldn't be any tie in to AutoSSL with this. What does "best certificate available" have to do with whether or not the certificate was issued with AutoSSL?
    0
  • cPRex Jurassic Moderator
    That all makes sense to me. I've created case CPANEL-42630 for our developers to look into this, and I'll keep this thread updated with my findings.
    0

Please sign in to leave a comment.