Hello,
I really love the integration of Let's Encrypt in Plesk, and I also love the extension security advisor to make easier the migration from http to https on wordpress websites.
But if I was already thinking if the third panel of Security advisor was really useful or not for normal users (because http/2 should be enabled by default and the plesk interface should be automatically protected with a SSL certificate) , other informations like KernelCare or Patchman were already very commercial.
So, I do not understand why Plesk enable by default the Symantec SSL certificates buttons , and require to use the panel.ini editor extension to disable it.
At first because , it 's already hard enough to explain to our customers the fact than let's encrypt provide the same level of security than any paid certificates, but also because Symantec is not really a good choice. They are selling their SSL certificates business to Digicert due to several security issues with their Certificate Authority in the past :
Timeline: Symantec certificate authority improprieties
If I do not have anything against the Symantec extension in Plesk, I do not think it should be enabled by default or promoted in Plesk.
I really love the integration of Let's Encrypt in Plesk, and I also love the extension security advisor to make easier the migration from http to https on wordpress websites.
But if I was already thinking if the third panel of Security advisor was really useful or not for normal users (because http/2 should be enabled by default and the plesk interface should be automatically protected with a SSL certificate) , other informations like KernelCare or Patchman were already very commercial.
So, I do not understand why Plesk enable by default the Symantec SSL certificates buttons , and require to use the panel.ini editor extension to disable it.
At first because , it 's already hard enough to explain to our customers the fact than let's encrypt provide the same level of security than any paid certificates, but also because Symantec is not really a good choice. They are selling their SSL certificates business to Digicert due to several security issues with their Certificate Authority in the past :
Timeline: Symantec certificate authority improprieties
If I do not have anything against the Symantec extension in Plesk, I do not think it should be enabled by default or promoted in Plesk.