Skip to main content

PCI Issues on port 21

Comments

3 comments

  • cPanelMichael
    Hello, Could you open a support ticket using the link in my signature so we can take a closer look at your system and see what's happening? You can post the ticket number here and we will update this thread with the outcome. Thank you.
    0
  • SJR
    I am with Trustwave also and I pass on port 21 with: FTP Server Configuration: TLS Encryption Support > Required (Command/Data) TLS Cipher Suite > (I use 'Modern Compatibility' on Mozilla TLS) Security/Server Side TLS - MozillaWiki And, if cipher DES-CBC3-SHA still shows up on scan, you can 'dispute' this finding by setting WHM > Service Configuration > Apache Configuration > Global Configuration > Keep Alive > OFF. My statement for the dispute was: KeepAlive is turned off on domain server The Service Configuration > Apache Configuration > Global Configuration > Keep Alive > OFF This setting is set to OFF. This directive disables all persistent connections. This is additionally confirmed by the setting in the apache config file: KeepAlive Off Trustwave approval message is: We have accepted this dispute based on information provided by your organization which indicates that this issue has been mitigated by limiting the length of TLS sessions with a 64-bit cipher. This is a workaround. Not sure why the ftp cipher list is not obeyed and other ciphers are seen on pci scan. Hope this helps.
    0
  • cPanelMichael
    Hello @SJR, Thank you for providing a workaround. Note that this topic is also discussed at: SOLVED - Securitymetrics - PCI fails on port 21 and 465 Thank you.
    0

Please sign in to leave a comment.