Support

Admin Tools

#26275 .well-known

Posted in ‘Admin Tools for Joomla!’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

DaveOzric
 Hello, I just installed 2 new Joomla sites and then Admin Tools. One I did the quick wizard one I did not.

Both sites have a pre defined entry in the Allow direct access, except .php files, to these directories of .well-known

I have never seen this before and wonder if you can tell me if this means anything to you.

Thanks

nicholas
Akeeba Staff
Manager
Please consult RFC 5785 for the meaning of the .well-known URL prefix i.e. the use of a .well-known folder in web sites. This is used, among other things, to confirm the ownership of a domain name when using Let's Encrypt or Keybase.io.

We added it as a default option in Admin Tools 4.0 on purpose. Many hosts which use cPanel now offer a single-click SSL certificate installation through Let's Encrypt. That makes use of the .well-known directory to verify ownership of the domain. If access to the directory is disabled by default –as it was in previous versions of Admin Tools– obtaining an SSL certificate automatically was impossible. Since there is no security threat from allowing web access to the non-executable contents of that directory and there is a great security value in HTTPS being widely used on as many sites as possible we decided to whitelist this directory by default.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

DaveOzric
OK thanks, just making sure nothing was awry.

Thanks for all your help and 7 years of security and not a single breach or issue!

Support Information

Working hours: Typically we work Monday to Friday, 9am to 7pm Cyprus timezone (EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets, but we cannot respond to them, outside of our working hours.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!

Summer vacations: Our support will be closed for replies and new tickets from August 6th to August 21st, 2022 due to summer vacations.