#26275 – .well-known

Posted in ‘Akeeba Admin Tools for Joomla!’
This is a public ticket. Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.
Friday, 07 October 2016 09:17 CDT
 Hello, I just installed 2 new Joomla sites and then Admin Tools. One I did the quick wizard one I did not.

Both sites have a pre defined entry in the Allow direct access, except .php files, to these directories of .well-known

I have never seen this before and wonder if you can tell me if this means anything to you.


Custom Fields

Joomla! version (in x.y.z format) 3.6.2
PHP version (in x.y.z format) 5.4
Admin Tools version (x.y.z format) 4.0.1
Friday, 07 October 2016 09:29 CDT
Please consult RFC 5785 for the meaning of the .well-known URL prefix i.e. the use of a .well-known folder in web sites. This is used, among other things, to confirm the ownership of a domain name when using Let's Encrypt or Keybase.io.

We added it as a default option in Admin Tools 4.0 on purpose. Many hosts which use cPanel now offer a single-click SSL certificate installation through Let's Encrypt. That makes use of the .well-known directory to verify ownership of the domain. If access to the directory is disabled by default –as it was in previous versions of Admin Tools– obtaining an SSL certificate automatically was impossible. Since there is no security threat from allowing web access to the non-executable contents of that directory and there is a great security value in HTTPS being widely used on as many sites as possible we decided to whitelist this directory by default.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native

🇬🇧English: excellent

🇫🇷French: basic

Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Friday, 07 October 2016 09:31 CDT
OK thanks, just making sure nothing was awry.

Thanks for all your help and 7 years of security and not a single breach or issue!
This ticket is closed, therefore read-only. You can no longer reply to it. If you need to provide more information, please open a new ticket and mention this ticket's number.

Support Information

Working hours: Typically we work Monday to Friday, 9am to 7pm Cyprus timezone (EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets, but we cannot respond to them, outside of our working hours.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!