Product Improvements: Flexible
Cloudways values its customers and their feedback! You can now give us your feedback on how we can improve Cloudways services, solution and products by pitching in your ideas!
92 results found
-
yubikey support
would be great to add hardware 2FA devices with fallback to google auth or SMS.. :)
7 votes -
Enable/ Disable mod_security
Please add Enable/ Disable for mod_security . This will increase our servers and applications security.
7 votes -
Enable Encrypted RDS MySQL Database
Enabling Encrypted MySQL Database on Amazon AWS would enable encryption at rest and improve security.
This would be a truly unique offering (trust me, I have been researching this for days), one that I can't believe isn't more requested or offered given the hacks and breaches we have seen over the last few years.
7 votes -
Provide alerts on successful SSH and SFTP login
Please provide alerts on successful SSH and SFTP logins to a server.
These alerts are important for visibility of when someone has accessed the server and making sure that access was expected.
6 votes -
Labels and wildcards for database whitelist
Add the ability to label IPs added to the remote DB whitelist so you can add your own identifier to IPs. And also add the ability to wildcard IPs by range eg. 5.40.%.%, and also the ability to add by domain name in addition to IP. This will allow for better management and greater control of whitelisted IPs
6 votes -
Add WAF module StackPath
Like done with CloudFlare and Sucuri a WAF module for StackPath's WAF would be great. So, one will be able to see the real IP - just like with CloudFlare and Sucuri
6 votes -
Force 2FA for Team Members
As account owner, I can setup 2FA on the main account, but I can't force my team members (some of whom have full access) to do so. This obviously creates a security loophole.
6 votes -
Cloud Firewalls
Will you offer a service similar to Cloud Firewalls, as provided by Digital Ocean? You can check the link here: https://blog.digitalocean.com/cloud-firewalls-secure-droplets-by-default/
6 votes -
Block other domains visibility from whois services
Hi, I'd like to suggest a new feature to server owner's security, to block other domains visibility from whois services. at the moment, anyone can go to any whois service (i.e. http://reverseip.domaintools.com) and by typing domain name, or the IP address can check what other domains are hosted on this server. i think, to privacy of users and server owners, this is a lack. it may be just an additional feature, but i'm sure people would love to see this as an option to disable this from public view.
5 votes -
5 votes
-
Audit / Security / Action Logs
It is critical for many businesses to be able check the actions and changes that are made on an account in order to debug, detect abnormal activities, intrusion or restoring certain setting back to their original, etc.
After discussing with the support on a separate ticket about an incident we detected as unusual, we felt the need for this feature more than ever.
Right now it is time consuming for support to check system logs and it is not easy to have a clear picture of WHAT happened and WHO did EXACTLY what and WHERE it was happening.
We got…
4 votes -
Show Two factor Auth status on Team page.
Users can turn on two-factor authentification in their account.
But there is currently no way to see if the team members you have in your team have enabled it. It makes it impossible to enforce two-factor auth and poses a security risk.Suggestion: Show "2FA enabled" next to team members that have enabled it on the Team page.
4 votes -
Provide an SSL badge for Cloudways users to display on their sites. Most SSL companies provide an HTML Coded badge for website users to see.
Provide an SSL badge for Cloudways users to display on their sites. Most SSL companies provide an HTML Coded badge for website users to click on which then opens a security check popup that shows that the site is, in fact, secure at the very moment of use. It's reassuring for users, especially on an e-commerce site, to know they are protected.
4 votes -
Two factor authentication - Mandatory for Team Members
Please add the ability for main/primary account holders to force TFA use for all Team Member accounts. Not having this capability (or the ability to see TFA status on Team Member accounts) is a significant security hole, of the type that could lead us to migrate away.
4 votes -
Check for the blacklist IP before assigning Server IP
Hello Team,
Can you please add some feature where it'll check for the blacklist before assigning server IP?
It seems like someone else was using assigned server IP before it's assigning to the user and they have abused the server so their IP is under blacklist and that blacklist server IP is not going to be useful for the new user.
4 votes -
4 votes
-
Integrate mod_evasive to mitigate DDoS attacks
DDoS issues are getting out of control. It would be a good idea to integrate mod_evasive apache module to mitigate them.
I was suggested by the support team to mitigate the attack using app level firewalls but that's far to be an optimal solution.
They confirmed that the current infrastructure of their servers is not ready for adding this apache module but they are open to evaluating it as an option.
4 votes -
Feature Request: Log analysis section
I made contact via suppot chat and ask if it was possible to install GoAccess on my server for a visual and accurate log view.
Since it was not possible all i can do is suggest to make a section on server panel to analyse server logs and have a clear vision of traffic and load.Gabriel G.
4 votes -
Allow disabling of weak SSH key exchange algorithms
PCI Compliance now regards weak ssh key exchange algorithms as a liability. There should be a way to disable them. It's fairly easy to set up in open-ssh: https://infosec.mozilla.org/guidelines/openssh#Configuration
4 votes -
OpenSSH 8.1 Upgrade
Needed for PCI/DSS compliance.
3 votes
- Don't see your idea?