#26275 – .well-known

Posted in ‘Akeeba Admin Tools for Joomla!’
This is a public ticket. Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.
Friday, 07 October 2016 09:17 CDT
 Hello, I just installed 2 new Joomla sites and then Admin Tools. One I did the quick wizard one I did not.

Both sites have a pre defined entry in the Allow direct access, except .php files, to these directories of .well-known

I have never seen this before and wonder if you can tell me if this means anything to you.

Thanks
Custom Fields
Joomla! version (in x.y.z format)
3.6.2
PHP version (in x.y.z format)
5.4
Admin Tools version (x.y.z format)
4.0.1
 
Friday, 07 October 2016 09:29 CDT
Please consult RFC 5785 for the meaning of the .well-known URL prefix i.e. the use of a .well-known folder in web sites. This is used, among other things, to confirm the ownership of a domain name when using Let's Encrypt or Keybase.io.

We added it as a default option in Admin Tools 4.0 on purpose. Many hosts which use cPanel now offer a single-click SSL certificate installation through Let's Encrypt. That makes use of the .well-known directory to verify ownership of the domain. If access to the directory is disabled by default –as it was in previous versions of Admin Tools– obtaining an SSL certificate automatically was impossible. Since there is no security threat from allowing web access to the non-executable contents of that directory and there is a great security value in HTTPS being widely used on as many sites as possible we decided to whitelist this directory by default.




Nicholas K. Dionysopoulos


Lead Developer and Director






Greek: native


English: excellent


French: basic






Please keep in mind my timezone and cultural differences when reading my replies. Thank you!






Friday, 07 October 2016 09:31 CDT
OK thanks, just making sure nothing was awry.

Thanks for all your help and 7 years of security and not a single breach or issue!
 
This ticket is closed, therefore read-only. You can no longer reply to it. If you need to provide more information, please open a new ticket and mention this ticket's number.

Support Information

Working hours: Typically we work Monday to Friday, 9am to 7pm Cyprus timezone (EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets, but we cannot respond to them, outside of our working hours.

Support policy: Read the complete support policy which is part of our Terms of Service. We kindly remind our subscribers that they have already explicitly and unconditionally accepted the Terms of Service.

Cookies Notification - Action required

This website uses cookies to provide user authentication and improve your user experience. Please indicate whether you consent to our site placing these cookies on your device. You can change your preference later, from the controls which will be made available to you at the bottom of every page of our site.