<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Moving Towards PCI Compliance with cPanel</title>
	<atom:link href="http://www.v-nessa.net/2008/04/14/moving-towards-pci-compliance-with-cpanel/feed" rel="self" type="application/rss+xml" />
	<link>http://www.v-nessa.net/2008/04/14/moving-towards-pci-compliance-with-cpanel</link>
	<description>pink is the new black</description>
	<lastBuildDate>Thu, 26 Jan 2012 17:17:54 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Benjie</title>
		<link>http://www.v-nessa.net/2008/04/14/moving-towards-pci-compliance-with-cpanel/comment-page-1#comment-9809</link>
		<dc:creator>Benjie</dc:creator>
		<pubDate>Sun, 05 Apr 2009 15:52:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.v-nessa.net/?p=151#comment-9809</guid>
		<description>I have returned to this website again and again. I cannot thank you enough! Steve&#039;s post, from 11/3/08, asks if the most recent version of cpanel, using native SSL resolves the issue. Well, I&#039;m using cPanel 11.24.4-R34548 - WHM 11.24.2 - X 3.9 and McAfee is unhappy.

I&#039;m working with the most excellent folks at HostMySite.com, who continually tolerate my noobness, and I&#039;ll post back if we find out anything.

Again, thank you, thank you, thank you!</description>
		<content:encoded><![CDATA[<p>I have returned to this website again and again. I cannot thank you enough! Steve&#8217;s post, from 11/3/08, asks if the most recent version of cpanel, using native SSL resolves the issue. Well, I&#8217;m using cPanel 11.24.4-R34548 &#8211; WHM 11.24.2 &#8211; X 3.9 and McAfee is unhappy.</p>
<p>I&#8217;m working with the most excellent folks at HostMySite.com, who continually tolerate my noobness, and I&#8217;ll post back if we find out anything.</p>
<p>Again, thank you, thank you, thank you!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve</title>
		<link>http://www.v-nessa.net/2008/04/14/moving-towards-pci-compliance-with-cpanel/comment-page-1#comment-9533</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Tue, 04 Nov 2008 00:47:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.v-nessa.net/?p=151#comment-9533</guid>
		<description>I have a system that keeps getting flagged by McAfee Secure&#039;s PCI scan and failing as a result of weak SSL ciphers for cPanel/WHM.

Have you done an upgrade to cPanel/WHM 11.24, and if so, did it resolve the weak SSL cipher issue?</description>
		<content:encoded><![CDATA[<p>I have a system that keeps getting flagged by McAfee Secure&#8217;s PCI scan and failing as a result of weak SSL ciphers for cPanel/WHM.</p>
<p>Have you done an upgrade to cPanel/WHM 11.24, and if so, did it resolve the weak SSL cipher issue?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nessa</title>
		<link>http://www.v-nessa.net/2008/04/14/moving-towards-pci-compliance-with-cpanel/comment-page-1#comment-9529</link>
		<dc:creator>Nessa</dc:creator>
		<pubDate>Thu, 30 Oct 2008 02:28:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.v-nessa.net/?p=151#comment-9529</guid>
		<description>Actually, I heard from a post in the cPanel forums from one of the developers that cPanel 11.24 will include the disabling of weak ciphers for all services.</description>
		<content:encoded><![CDATA[<p>Actually, I heard from a post in the cPanel forums from one of the developers that cPanel 11.24 will include the disabling of weak ciphers for all services.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kelly</title>
		<link>http://www.v-nessa.net/2008/04/14/moving-towards-pci-compliance-with-cpanel/comment-page-1#comment-9526</link>
		<dc:creator>Kelly</dc:creator>
		<pubDate>Wed, 29 Oct 2008 21:37:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.v-nessa.net/?p=151#comment-9526</guid>
		<description>Actually, having cpanel set to running native ssl is still a  problem. The weak ciphers and sslv2 are enabled on the cpanel ssl ports, and the hackeralert scans flag this. I am looking for a way to disable this without having to run stunnel. I cant seem to find any solution other than to install and run stunnel. There must be some way to fix this.</description>
		<content:encoded><![CDATA[<p>Actually, having cpanel set to running native ssl is still a  problem. The weak ciphers and sslv2 are enabled on the cpanel ssl ports, and the hackeralert scans flag this. I am looking for a way to disable this without having to run stunnel. I cant seem to find any solution other than to install and run stunnel. There must be some way to fix this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nessa</title>
		<link>http://www.v-nessa.net/2008/04/14/moving-towards-pci-compliance-with-cpanel/comment-page-1#comment-9499</link>
		<dc:creator>Nessa</dc:creator>
		<pubDate>Thu, 16 Oct 2008 13:32:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.v-nessa.net/?p=151#comment-9499</guid>
		<description>You should be able to do this in WHM &gt; tweak settings by having cpanel use native ssl support instead of stunnel.</description>
		<content:encoded><![CDATA[<p>You should be able to do this in WHM > tweak settings by having cpanel use native ssl support instead of stunnel.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: oly</title>
		<link>http://www.v-nessa.net/2008/04/14/moving-towards-pci-compliance-with-cpanel/comment-page-1#comment-9492</link>
		<dc:creator>oly</dc:creator>
		<pubDate>Tue, 14 Oct 2008 14:25:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.v-nessa.net/?p=151#comment-9492</guid>
		<description>How do you keep secure cpanel ports from using weak ciphers? Here is a sample of tls1 supporting weak cipher:

New, TLSv1/SSLv3, Cipher is EXP-RC2-CBC-MD5
Server public key is 1024 bit
SSL-Session:
    Protocol  : TLSv1
    Cipher    : EXP-RC2-CBC-MD5</description>
		<content:encoded><![CDATA[<p>How do you keep secure cpanel ports from using weak ciphers? Here is a sample of tls1 supporting weak cipher:</p>
<p>New, TLSv1/SSLv3, Cipher is EXP-RC2-CBC-MD5<br />
Server public key is 1024 bit<br />
SSL-Session:<br />
    Protocol  : TLSv1<br />
    Cipher    : EXP-RC2-CBC-MD5</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Primsi</title>
		<link>http://www.v-nessa.net/2008/04/14/moving-towards-pci-compliance-with-cpanel/comment-page-1#comment-9329</link>
		<dc:creator>Primsi</dc:creator>
		<pubDate>Wed, 28 May 2008 11:52:15 +0000</pubDate>
		<guid isPermaLink="false">http://www.v-nessa.net/?p=151#comment-9329</guid>
		<description>Did anybody try to include

ServerSignature Off
ServerTokens Prod
FileETag None

via the Include Editor in WHM &gt; Apache Setup? There are tree possible places to include it Pre Main Include, Pre VirtualHost Include and Post VirtualHost Include.Is it &#039;Pre VirtualHost&#039;?</description>
		<content:encoded><![CDATA[<p>Did anybody try to include</p>
<p>ServerSignature Off<br />
ServerTokens Prod<br />
FileETag None</p>
<p>via the Include Editor in WHM &gt; Apache Setup? There are tree possible places to include it Pre Main Include, Pre VirtualHost Include and Post VirtualHost Include.Is it &#8216;Pre VirtualHost&#8217;?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: www.tagsto.com/trackback/</title>
		<link>http://www.v-nessa.net/2008/04/14/moving-towards-pci-compliance-with-cpanel/comment-page-1#comment-9270</link>
		<dc:creator>www.tagsto.com/trackback/</dc:creator>
		<pubDate>Fri, 09 May 2008 22:50:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.v-nessa.net/?p=151#comment-9270</guid>
		<description>&lt;strong&gt;Shops of Moving Towards PCI Compliance with cPanel...&lt;/strong&gt;

shops about  to After dealing with 2-3 PCI scans a week for the last year, I’ve put together a common procedure for how to make your server compliant to current PCI standards. Note that each scan company is different and may report other issues, ......</description>
		<content:encoded><![CDATA[<p><strong>Shops of Moving Towards PCI Compliance with cPanel&#8230;</strong></p>
<p>shops about  to After dealing with 2-3 PCI scans a week for the last year, I’ve put together a common procedure for how to make your server compliant to current PCI standards. Note that each scan company is different and may report other issues, &#8230;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Brandonisio</title>
		<link>http://www.v-nessa.net/2008/04/14/moving-towards-pci-compliance-with-cpanel/comment-page-1#comment-9266</link>
		<dc:creator>Mike Brandonisio</dc:creator>
		<pubDate>Thu, 08 May 2008 21:50:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.v-nessa.net/?p=151#comment-9266</guid>
		<description>Hi,

Sorry, These files should be updated too:

/var/cpanel/templates/apache2/ssl_vhost.default                                                               /var/cpanel/templates/apache2/ssl_vhost.local 

With:

SSLProtocol -ALL +SSLv3 +TLSv1
SSLCipherSuite ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>Sorry, These files should be updated too:</p>
<p>/var/cpanel/templates/apache2/ssl_vhost.default                                                               /var/cpanel/templates/apache2/ssl_vhost.local </p>
<p>With:</p>
<p>SSLProtocol -ALL +SSLv3 +TLSv1<br />
SSLCipherSuite ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Brandonisio</title>
		<link>http://www.v-nessa.net/2008/04/14/moving-towards-pci-compliance-with-cpanel/comment-page-1#comment-9265</link>
		<dc:creator>Mike Brandonisio</dc:creator>
		<pubDate>Thu, 08 May 2008 20:54:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.v-nessa.net/?p=151#comment-9265</guid>
		<description>Hi,

When making the Weak cypher changes for apache SSL, consider making the similar updates to:

/usr/local/apache/conf/httpd.conf.default

for future sites on your cpanel server. Otherwise they will get the same weak cypher directive in the virtual host section.

Thanks for the PCI compliance post.

Mike</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>When making the Weak cypher changes for apache SSL, consider making the similar updates to:</p>
<p>/usr/local/apache/conf/httpd.conf.default</p>
<p>for future sites on your cpanel server. Otherwise they will get the same weak cypher directive in the virtual host section.</p>
<p>Thanks for the PCI compliance post.</p>
<p>Mike</p>
]]></content:encoded>
	</item>
</channel>
</rss>

