• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Issue Error message ID 19494#0, 5467#0 and ModSecurity

User22123

Basic Pleskian
Dear support team, dear community. I'm new and I have some questions and I ask for your valued help as I still lack some experience.

I get these error messages in the logs below. I read to use SSL it on the first two errors, which I do. Nevertheless, these error messages keep coming for all domains.

A domain running on Cloudflare has the same problem.

I hope you can help me and thank you in advance for your time

19494#0: *2346 openat() "/var/www/vhosts/default/htdocs/.well-known/acme-challenge/............................." failed (2: No such file or directory)
5467#0: *46580 openat() "/var/www/vhosts/default/htdocs/.well-known/acme-challenge/............................." failed (2: No such file or directory)

[client IP ADRESS] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/modsecurity.d/rules/comodo_free/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||domain|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "domain"] [uri "/template/uploads/dump.sql"] [unique_id "......."], referer: https://domain/

[client IP ADRESS] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/modsecurity.d/rules/comodo_free/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||domain|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "domain"] [uri "/template/debug.log"] [unique_id "YkzIuo08QIdf41IrmdbpNgAAAEI"], referer:domain/
 
Dear support team, dear community. I'm new and I have some questions and I ask for your valued help as I still lack some experience.

I get these error messages in the logs below. I read to use SSL it on the first two errors, which I do. Nevertheless, these error messages keep coming for all domains.

A domain running on Cloudflare has the same problem.

I hope you can help me and thank you in advance for your time

19494#0: *2346 openat() "/var/www/vhosts/default/htdocs/.well-known/acme-challenge/............................." failed (2: No such file or directory)
5467#0: *46580 openat() "/var/www/vhosts/default/htdocs/.well-known/acme-challenge/............................." failed (2: No such file or directory)

[client IP ADRESS] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/modsecurity.d/rules/comodo_free/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||domain|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "domain"] [uri "/template/uploads/dump.sql"] [unique_id "......."], referer: https://domain/

[client IP ADRESS] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/modsecurity.d/rules/comodo_free/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||domain|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "domain"] [uri "/template/debug.log"] [unique_id "YkzIuo08QIdf41IrmdbpNgAAAEI"], referer:domain/
@User22123 Did you get a solution to this one?
 
In this case it could help to describe in better detail what is being done, what is the expected output, what is the factual output and where the log lines stated in the initial posts are coming from. Especially for the first two log lines it remains unclear what these are. Are these entries in error_log, access_ssl_log or elsewhere? And are these log entries a result from a certificate installation, renewal, removal or visiting a website?
 
Back
Top