ModSecurity Domain Manager: SecRuleEngine On never rendered in compiled httpd.conf — missing ELSE branch in vhost.default template
Environment:
- cPanel version: 138.0.6
- OS: CloudLinux v8.10.0 (KVM)
- Apache/EA4, mod_security2
Summary:
Enabling ModSecurity for a domain via cPanel's "Security → ModSecurity" Domain Manager (or via uapi ModSecurity enable_domains, or /usr/local/cpanel/bin/modsecuritydomains enable) correctly updates the account's userdata (secruleengineoff: 0 is written to /var/cpanel/userdata/<user>/<domain> and its _SSL counterpart), but the compiled /etc/apache2/conf/httpd.conf never actually emits a SecRuleEngine On directive for that vhost. This holds regardless of /scripts/rebuildhttpdconf, /scripts/updateuserdatacache, or a full Apache restart — the domain stays functionally unprotected even though the UI and userdata both report it as enabled.
Root cause:
/var/cpanel/templates/apache2_4/vhost.default (same pattern in ssl_vhost.default), around line 153:
[%- IF vhost.secruleengineoff %]
<IfModule security2_module>
SecRuleEngine Off
</IfModule>
<IfModule security3_module>
modsecurity_rules 'SecRuleEngine Off'
</IfModule>
[%- END %]
There is no ELSE branch emitting SecRuleEngine On (or any directive) when secruleengineoff is 0. The template can only ever produce "Off" or nothing at all — it structurally cannot turn ModSecurity on for a domain.
Steps to reproduce:
-
uapi --user=<user> ModSecurity enable_domains domains=<domain>(requires themodsecuritycPanel feature to be enabled for the account). - Confirm
secruleengineoff: 0is written to/var/cpanel/userdata/<user>/<domain>[._SSL]. - Rebuild the Apache config (
/scripts/rebuildhttpdconf, or via cPanel's ownCpanel::ConfigFiles::Apache::vhost::update_users_vhosts($user)— the same function the Domain Manager UI itself calls). - Inspect the compiled vhost block for that domain in /etc/apache2/conf/httpd.conf — no
SecRuleEngine Onis present.
Already ruled out:
- Stale userdata cache — confirmed fresh (
secruleengineoff: 0present) - Stale compiled httpd.conf — confirmed freshly rewritten (matching mtime) immediately after calling the exact function the UI uses, still missing the directive
- Apache not picking up new config — ruled out via full
systemctl restart httpd - Toggling off then on again via the UI itself — no change
Happy to provide further detail if useful. Is this a known/tracked defect?
-
Hey there! Thanks so much for reporting this - I've filed case CPANEL-56903 with our team so they can get this resolved.
I've linked this thread to the case so I'll be sure to post an update if I hear anything else on my end.
0
Please sign in to leave a comment.
Comments
1 comment