• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • We are looking for U.S.-based freelancer or agency working with SEO or WordPress for a quick 30-min interviews to gather feedback on XOVI, a successful German SEO tool we’re looking to launch in the U.S.
    If you qualify and participate, you’ll receive a $30 Amazon gift card as a thank-you. Please apply here. Thanks for helping shape a better SEO product for agencies!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

AWStats access protection incompatible with Apache 2.4, causes "client denied by server configuration", triggers fail2ban

Bitpalast

Plesk addicted!
Plesk Guru
Username: Peter Debik

TITLE

AWStats access protection incompatible with Apache 2.4, causes "client denied by server configuration", triggers fail2ban

PRODUCT, VERSION, OPERATING SYSTEM, ARCHITECTURE

Obsidian 18.0.32, latest MU
CentOS 7.9

PROBLEM DESCRIPTION

Issue appears since update from Onyx 17.8 to Obsidian 18.0.32. With the ugprade, it seems that a change was made to Apache, too. Now this happens:

When a customer opens AWStats, he is prompted to enter the FTP user name and password. After entering the credentials, access is granted. But on many files, still a "client denied by server configuration" is logged (although access was granted). We think it is the same issue described here:

The article is about Prestashop, but the behavior is the same, and after the upgrade from Onyx to Obsidian we have seen many cases where the same solution was also needed for other software, not only Prestashop. Our clients are now describing the same issue with AWStats password protection, so it is quite likely that this has the same cause, because there have not been issues before.

STEPS TO REPRODUCE

Password-protect the statistics directory, login, click around in some sub pages.

ACTUAL RESULT

"client denied by server configuration" will be logged although login was correct. Fail2ban reads the entry in the logs, uses the Apache jail and blocks access for the requesting IP.

EXPECTED RESULT

No "client denied by server configuration" logged.

ANY ADDITIONAL INFORMATION



YOUR EXPECTATIONS FROM PLESK SERVICE TEAM

Confirm bug
 
Back
Top