⛔ New Security Advisor notifications with High importance

stokmu

Member
Jun 8, 2022
17
3
3
Indonesia
cPanel Access Level
Root Administrator
⛔ HighApacheApache vhosts are not segmented or chroot()ed. Enable "mod_ruid2" in the "EasyApache 4" area, enable "Jail Apache" in the "Tweak Settings" area, and change users to jailshell in the "Manage Shell Access" area. Consider a more robust solution by using "CageFS on CloudLinux". Note that this may break the ability to access mailman via Apache.
And

⚠ MediumApacheLiteSpeed vhosts are not segmented or chroot()ed. Consider a more robust solution by using "CageFS on CloudLinux".

how to solve this?
Thank you very much
 
Dec 12, 2022
10
6
3
United States
cPanel Access Level
Root Administrator
I manage other WHMs and I am getting similar messages on them too. I have them all setup the same way. I noticed after a recent update the shell access was changed from jailed to disabled. I moved them back to jailed for ssh access. To be safe we use the security advisor after any yum update requiring a reboot.
 
Dec 12, 2022
10
6
3
United States
cPanel Access Level
Root Administrator
We have been using it for years without any issues. Though in your screenshot it is greyed out. To use it you have to run mod_mpm_prefork in the Apache4 setup. We are WordPress folks and minimal WHM admins looking to get away from the traditional shared hosting since 2008. Things like the world are getting a little squirrelly. And then there is the constant upsell. Just trying to keep it simple, safe and affordable for our customers.
 
  • Like
Reactions: jcbfergie

jcbfergie

Member
Aug 1, 2018
5
1
1
Mississippi
cPanel Access Level
Root Administrator
Hi ,
We are also facing the same issue in almost every WHM/cpanel installed machine . As @cPRex wisely suggested that its up to us to enable it or not , but then the Jailshell feature Apache is an Experimental Feature and not announced as stable so as to enable it and use . In such case what do you suggest.
I enabled mod_ruid2, and I changed to jailshell, but I also can't enable this item because it is grayed out. I found where to enable mod_mpm_prefork, but it has beside it "2.4.54-2.el7.cloudlinux" - Do I need to have cloudlinux to enable this feature? Because I don't have it..