Host Access Control to automatically add cphttpd rules on DNSOnly Servers for SSL issurance
As a System Administrator, I would like:
cPanel DNSOnly servers to automatically add appropriate rules for Sectigo into the "Host Access Control" / /etc/hosts.allow file when AutoSSL runs (either via checkallsslcerts/upcp or other method)
so that
SSL certificates are able to be automatically requested and installed without server administrators having to diagnose this issue manually.
Failing that (i.e. quick fix)
Perhaps add messaging to the top of the Host Access Control detailing that this is needed for server SSL certificates (i.e. "To allow for SSL certificates to be issued, please add "Allow" records for your server IP address(es) and those listed by your certificate issuer for the daemon "cphttpd" )
Background
This feature request follows on from support ticket #94466527 "DNSOnly server SSL issues due to Host Access Controls not listing cphttpd as a service" (see also CPANEL-41149 article and internal case ID DOC-18245)
For full context please feel free to read my blog entry which details all the investigation steps, failures and findings I made when sorting this out.
Replies have been locked on this page!