Follow along with the video below to see how to install our site as a web app on your home screen.
Note: This feature may not be available in some browsers.
We value your experience with Plesk during 2024 Plesk strives to perform even better in 2025. To help us improve further, please answer a few questions about your experience with Plesk Obsidian 2024. Please take this short survey: https://pt-research.typeform.com/to/AmZvSXkx
The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
Username:
TITLE
Disabled PHP "Hosting performance settings management" can be bypassed by using .user.ini or ini_set()
PRODUCT, VERSION, OPERATING SYSTEM, ARCHITECTURE
Plesk Obsidian 18.0.61 Update #6, Debian 12.6, x86-64
PROBLEM DESCRIPTION
Even though we disallow the usage of...
@Aleksei Fedorov Thanks for your reply, but in this case, all settings made by our clients via .user.ini would not work anymore. This is not an option. Furthermore, clients could still change the value inside PHP scripts with ini_set('memory_limit', '512M'); . Disabling ini_set() completely is...
Hello,
If the "Hosting performance settings management" is disabled in a service plan, users can still override settings like memory_limit or max_execution_time, e.g., via the .user.ini file in their subscriptions.
I think many Plesk users disable that feature and believe that clients are not...
The reason behind is a different system logging daemon.
The upgraded Debian 12 systems are normally using rsyslog as default system and kernel logging daemon. Installing Plesk on a fresh Debian 12 installation leads to the usage of syslog-ng as default system logging daemon.
Is there any...
Lately we had the some anomaly as @Bitpalast . We could not remove subdomains and/or domain aliases / domains from the administrator domain view using the menu with the three dots. When switching to the remove button everything worked out fine.
Same es @Kaspar@Plesk we could not reproduce the...
We never had an empty certificate request confirmation box in the moment, when a new certificate request was initiated manually. Maybe you should open an own bug report as my one is related to a different issue - the renewal of already existing wildcard certificates that are also used for...
As it was not mentioned in the changelog - if you want to disable the paid and advertised "Vulnerability Protection" feature set the following rule in your "Panel.ini Editor":
[ext-wp-toolkit]
virtualPatchesFeature = false
Hello @SalvadorS ,
it could also be a "bad crawler" that brings your site down. We had this a lot recently too even though we are using a very good firewall to block most of such bad networks where the crawlers coming from.
Just check your access log of the domain affected with the following...
We can confirm now, that the first domain + subdomain setups with one wildcard certificate did renew correctly without any issues. That looks promising. Let's wait one more week to be sure. Only combinations with an already broken renewal status are still problematic. The Plesk team is on it but...
Clicking "Cancel" did work for us. Later the wildcard certificate was renewed correctly and assigned to the main domain plus subdomain.
We have another server with the same issue. The certificate is not due yet but we still have an old order including the "Cancel" button. We did install the...
We did it but it has no effect. Looks like the bugfix does not work for our case. We did click now "Cancel". Let's wait another 24 hours if at least the certificate gets renewed.
The affected certificate of domain + subdomain was not renewed and shows still the known buggy behavior:
Does the new version take care already "broken" renewal processes?
Is there any ETA for a bugfix? We get a lot of negative response from our clients that they are forced to make the 2FA every time they login again. Especially admins are annoyed.
We did install the latest version on one of our smaller servers that is affected by this bug (only 8 domains hosted in total on that server). At the moment we still see the bug for one combination of domain + subdomain using the same SSL certificate (certificate will expire in 18 days and is in...
@learning_curve The command...
... should be used carefully. Plesk has temporary sources while updating the base system (e.g. 50sw_autoinstaller.list). In that moment many packages are not in the list of "Obsolete and Locally Created Packages" anymore. After the update procedure is finished...
@learning_curve We did not experience such problems but we did only uninstall packages from the previous OS. The "old/obsolete" packages from the current OS are still in place.
We had nearly 150 Debian 10 packages left after upgrading from Debian 10 to 11. All dependencies were connected in some way to Plesk packages. Originally this came to our attention because some dependency warnings were thrown in the upgrade process.
You can check your Debian systems to find the...
Maybe as additional information for the developers of Plesk directly here in the bug report:
- This issue did also disappear in other affected areas (e.g. PHPMyAdmin / [...]).
- Reverse proxying was also affected: we have special domains that are reverse proxying the Plesk admin panel to have...