cPanel Web Services Configuration

Valid for versions 88 through the latest version



Last modified: 2024 June 13

Looking for this interface?

Your hosting provider can enable or disable this interface for resellers in WHM's Edit Reseller Nameservers and Privileges interface (WHM >> Home >> Resellers >> Edit Reseller Nameservers and Privileges).


The system uses cipher suites to negotiate security settings for network connections over TLS/SSL. This interface allows you to edit the TLS/SSL Cipher List and TLS/SSL Protocol list for cPanel, WHM, and Webmail.


We recommend that only advanced users edit the cipher and protocol lists.


cPanel & WHM supports Transport Layer Security (TLS) protocol version 1.2 and Transport Layer Security (TLS) protocol version 1.3:

  • cPanel & WHM only supports TLSv1.2 or later. The system enables TLSv1.2 by default.
  • Not all clients will support TLSv1.3, which requires OpenSSL 1.1.1 or higher.


By default, cPanel & WHM uses the following cipher list for web services:


By default, cPanel & WHM uses the following protocol list for web services:


Edit the cipher list

To edit the cipher list, enter the appropriate cipher in the text box and click Save.

  • The default cipher list is PCI compliant. To edit the cipher list to improve the security level on your server, read Apache’s SSLCipherSuite Directive documentation.

  • We do not recommend that you edit the cipher list to lower the security level. Make certain that the cipher suite uses at least 128-bit encryption.

Edit the protocol list

To edit the protocol list, enter the appropriate protocol list in the text box and click Save.

Additional Documentation