{"id":45765,"date":"2017-07-10T08:09:18","date_gmt":"2017-07-10T13:09:18","guid":{"rendered":"https:\/\/blog.cpanel.com\/?p=45765"},"modified":"2017-07-10T08:09:18","modified_gmt":"2017-07-10T13:09:18","slug":"urgent-dcv-updates-this-week","status":"publish","type":"post","link":"https:\/\/devel.www.cpanel.net\/blog\/products\/urgent-dcv-updates-this-week\/","title":{"rendered":"Urgent DCV Updates This Week"},"content":{"rendered":"

Versions with the updates have been added to the bottom of this post!<\/h1>\n

———————————————-<\/h2>\n

The\u00a0cPanel Market<\/a>\u00a0SSL Provider allows webhosts to easily sell DV, EV, and OV SSL certificates through cPanel. Similarly,\u00a0AutoSSL<\/a>\u00a0automatically requests and installs free SSL certificates for hosted domains. Both of these features allow you to install SSL certificates issued by cPanel, and signed by Comodo.<\/p>\n

Late last week we were alerted to changes that Comodo is making to how they handle domain verification. If you have cPanel & WHM updates set to automatically be applied, then you don’t need to worry about anything at all. However,\u00a0if you manage your updates manually, you need to pay attention.<\/strong><\/p>\n

DCV<\/h2>\n

Domain Control Validation (DCV) is the act of verifying that a user is the one who controls a domain. Both the cPanel Market SSL Provider and AutoSSL use files our software creates in a website’s document root (on most cPanel accounts: \/home\/user\/public_html\/) to verify that the server requesting the SSL controls the domain. The changes that Comodo is making touch on the very core of cPanel’s DCV.<\/p>\n

Comodo DCV Updates<\/h2>\n

The list of things Comodo is changing includes both the contents of the file, and the directory in which it will be looking. Rather than looking in a website’s document root directly, it will now look inside a folder named .well-known<\/em>\u00a0inside the document root.<\/p>\n

For example, right now the DCV check will look for\u00a0HTTP(S):\/\/fully.qualified.name\/<filename.txt><\/em>. After the change is released the DCV check will look for \u00a0HTTP(S):\/\/fully.qualified.name\/.well-known\/pki-validation\/<filename.txt><\/em>\u00a0to validate the domain.<\/p>\n

When you need to upgrade<\/h2>\n

For now both the “old” and the “new” ways of validating domains will continue to work. The “old” way will no longer be supported after July 20, 2017. Over the weekend our development team worked hard to get code written and tests updated to reflect these changes. These updates will apply to all supported versions of cPanel & WHM: version 56 through 66.<\/p>\n

Comodo’s changes are live today, so we’re going to be testing extensively over the next few days before releasing our updates to the public. Assuming an ideal timeline, we will release updates for all versions this week, in plenty of time for the deadline on July 20th.<\/p>\n

Anticipated question\/answer rundown<\/h2>\n