• We value your experience with Plesk during 2024
    Plesk strives to perform even better in 2025. To help us improve further, please answer a few questions about your experience with Plesk Obsidian 2024.
    Please take this short survey:

    https://pt-research.typeform.com/to/AmZvSXkx
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Thousands of SSL challenge files left in /var/www/vhosts/default/htdocs/.well-known/acme-challenge

Bitpalast

Plesk addicted!
Plesk Guru
TITLE:
Thousands of SSL challenge files left in /var/www/vhosts/default/htdocs/.well-known/acme-challenge
PRODUCT, VERSION, OPERATING SYSTEM, ARCHITECTURE:
Onyx 17.8
CentOS 7.6 latest MU
Latest Let's Encrypt extension version
PROBLEM DESCRIPTION:
SSL challenge files are left in /var/www/vhosts/default/htdocs/.well-known/acme-challenge and are never deleted. On our systems we see well over 100,000 files in these directories.​
STEPS TO REPRODUCE:
Create a certificate​
ACTUAL RESULT:
See challenge file in /var/www/vhosts/default/htdocs/.well-known/acme-challenge​
EXPECTED RESULT:
Should be deleted once the authentication process is completed.​
ANY ADDITIONAL INFORMATION:
See thread Let's Encrypt extension on this.
YOUR EXPECTATIONS FROM PLESK SERVICE TEAM:
Confirm bug
 
I've just deleted 455 file from this directory, these files created while testing just for one single domain.
I can confirm this bug also on Plesk Obsidian 18.16 + 18.17
SSLit could be the root of this.
 
Our instances are without SSLit, but the issue is present.

Plesk Onyx 17.8.11 Update #65
Let's Encrypt Extenion 2.8.2-529
CentOS 7.6.1810

(all latest at this time)
 
Then it's lets encrypt
This improvement could be the case somewhere in
Change Log for Plesk

Improved chances of successful Let’s Encrypt HTTP challenge validation by using general locations for .well-known/acme-challenge. This helps issue an SSL/TLS certificate if a domain has some specially configured rewrite rules (certain web applications configure them by default) or access restrictions. You can revert this improvement by adding the following lines to the panel.ini file:
Code:
[ext-letsencrypt]
 use-common-challenge-dir = false

Or just a simple cron task doesn't clean up the tokens. stop predicting :cool:
 
Back
Top