Hi everyone,
We are happy to announce that Plesk Onyx 17.5 is now officially out and available for installation! To browse the list of new features, latest supported OSes and components, refer to Plesk Onyx 17.5 Release Notes:
What's New in Plesk
We would like to hear your opinion about Plesk Onyx 17.5, especially if you're deploying it on production servers - please let us know what are your favorite features in this release and what would you like to see in the next Plesk version.
Hello Plesk (Igor),
I am loving the new Onyx installation. Lost one of my Plesk production servers lately due to half-assed firewall configurations and software management. When upgrading to Plesk Onyx I was pleased to notice that features like Fail2Ban, Watchdog (Monit and rkhunter), firewall, ModSecurity, DNSSEC, etc.. Were already integrated and preconfigured, install with the click of a button.
Because I felt I didn't have enough protection and oversight I added Maltrail manually to Plesk. Writing jails and filters for the observed behaviour was easily done through the Plesk interface. I also find the (Plesk) interface useful to check if the IP address was in fact banned (and by which jails).
I've installed Plesk Onyx on a Debian that upgraded from 7 to 8 and it runs very smooth. No issues there.
For me LetsEncrypt SSL certificates and auto-renewal are very useful because it saves me from having to insert and renew certificates manually. However some of my whitelisted domains still need to be manually updated because the whitelist does not allow LE IP's. LE auto-renewal IP's change so now and then and I haven't found a suitable solution yet. Also it might be useful to preconfigure the webmail.example.com domains to be able to automatically renew themselves without having to turn the mail off or configure Nginx with a rule. Or have a checkbox to configure this for the subdomain. Currently the webmail catches the renewal process and it fails.
So far I haven't been able to get docker running (even with the updated kernel 3.10+). But I expect this to be a problem with my hosting providers virtualization software. You might want to add some extra warning in the documentation about the minimum requirements for the virtualization software the hosting company uses.
Things I think might need some attention:
- rkHunter is running version 1.3.4 (think I read somewhere this was going to update).
- LetsEncrypt being able to auto-renew proxied domains. For example by ignoring the proxy.
- Running web applications without having to configure Nginx/Apache (I know this is difficult because it's prone to change).
- Whitelisting certain domains
So far I am very pleased.
Kind regards,
Neodork
Edit: Move me to 17.0 Onyx feedback thread!