• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Forwarded to devs SELinux Interferes with Plesk FTP Backup

J.Wick

Regular Pleskian
Username:

TITLE

SELinux Interferes with Plesk FTP Backup

PRODUCT, VERSION, OPERATING SYSTEM, ARCHITECTURE

Plesk Obsidian Version 18.0.46 Update #1
Rocky Linux 8.6

PROBLEM DESCRIPTION

Migrated Plesk from Centos 7.9 over to a new server with Rocky Linux 8.6 and could not connect to our remote FTPS backup server successfully.

STEPS TO REPRODUCE

Entered known working settings for FTPS (Non-PASV) on custom port 2121/TCP into Plesk Backup Remote Storage and clicked 'Apply.'

ACTUAL RESULT

Plesk partially connected to the FTP and timed out, producing an error, with a CURL troubleshooting command that worked when tried at the CLI.

EXPECTED RESULT

Should quickly connect and report successful connection.

ANY ADDITIONAL INFORMATION

Turning on firewall drop packet logging, I saw the outbound connection was creating many FINAL_REJECT log entries.

SELinux was discovered after a day of troubleshooting it was blocking the outbound connection. After disabling SELinux and rebooting, the connection was successful.

SELinux is important technology; I'd like to re-enable it, but administrators need a way to know about situations like this and have fast ways to correct them. Plesk should be more intelligent in handling SELinux alerts and have a method to recognize non-standard ports in the Backup Manager FTP settings and adjust SELinux accordingly as part of its FTP connection test.

A Tools & Settings -> Security -> SELinux Security panel would be a great feature addition.

YOUR EXPECTATIONS FROM PLESK SERVICE TEAM

Confirm bug
 
The issue was not reproduced in the test environment.

On test RockyLinux with Plesk SELinux is enabled in enforcing mode:

[root@deonte-gxzhy7 ~]# sestatus
SELinux status: enabled
SELinuxfs mount: /sys/fs/selinux
SELinux root directory: /etc/selinux
Loaded policy name: targeted
Current mode: enforcing

On the second server with CentOS 7 vsftpd server was installed and FTP default port was changed to 2121

FTPS was successfully configured in Plesk. More technical details is required to find out the cause with SELinux in your case. I would suggest creating a ticket to Plesk Technical Support to investigate the issue further.

A Tools & Settings -> Security -> SELinux Security panel would be a great feature addition.

The GUI implementation is a feature request:
SeLinux management in Plesk GUI
 
Back
Top