FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Hosting
  4. MiniServ
M

MiniServ

OtherWebsite

Related services

A

actionhero.js

actionhero.js is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. actionhero.js integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, actionhero.js helps organizations maintain robust websites that meet user expectations and technical requirements.

Other

Adminer

Adminer is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Adminer supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Adminer ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Akka HTTP

Akka HTTP is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. Akka HTTP integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, Akka HTTP helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
A

Alibaba Cloud Object Storage Service

Alibaba Cloud Object Storage Service is a web hosting and cloud infrastructure provider delivering reliable, scalable hosting solutions for websites and applications of all sizes. It offers shared, VPS, and dedicated server options with SSD storage, global CDN, and automated backups. Alibaba Cloud Object Storage Service provides one-click deployment, managed databases, and 24/7 monitoring. With high uptime guarantees and developer-friendly tools, Alibaba Cloud Object Storage Service ensures optimal.

Other

AlmaLinux

AlmaLinux is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AlmaLinux supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AlmaLinux ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

AlternC

AlternC is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. AlternC supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, AlternC ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does MiniServ do?

MiniServ is the lightweight Perl based web server that powers Webmin and Usermin, serving the system administration interface over HTTPS and setting a strictly necessary session cookie to authenticate administrators.

MiniServ is the lightweight, Perl based web server that powers Webmin and Usermin, the popular open source tools for administering Unix and Linux systems. It runs directly on the administrator own server and serves the management interface over HTTPS, handling authentication, access control and encrypted connections without relying on any external service.

What MiniServ is

MiniServ, implemented in the script miniserv.pl, is the built in web server that both Webmin and Usermin use to deliver their administration panels. It is a first party, self hosted component that you install and run on your own infrastructure. It is not a visitor analytics tool and it does not load third party trackers or advertising scripts. Its only job is to securely present the administration interface to the people who manage the server.

Data and the session cookie

When an administrator signs in, MiniServ sets a first party session cookie, commonly named sid, and may use a short lived testing cookie to confirm that the browser accepts cookies. This cookie keeps the administrator logged in for the duration of the session and is the standard mechanism behind Webmin session authentication mode. The cookie holds only an opaque session identifier, not credentials, and over HTTPS it is issued with the secure and httpOnly flags so it cannot be read by scripts or sent over an unencrypted connection.

GDPR and ePrivacy implications

The MiniServ session cookie is strictly necessary to provide the service that the administrator explicitly requested, namely a secure login. Under Article 5(3) of the ePrivacy Directive, cookies that are strictly necessary to deliver a service the user asked for are exempt from the consent requirement. The minimal processing involved rests on the operator legitimate interest under Article 6(1)(f) GDPR in securing access to its own systems, so MiniServ raises only limited data protection concerns when it is used as intended.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

Because the session cookie is strictly necessary for authentication, no prior consent or cookie banner is required for it. The interface is reached only by administrators who deliberately log in, not by general visitors, so there is no tracking that would trigger a consent obligation. You should still describe the cookie transparently in any internal privacy notice that covers your administration tools.

Data transfers

MiniServ is entirely self hosted, so it does not transmit personal data to any third party or to servers outside your own infrastructure. There is no transfer to third countries to assess, because the session data never leaves the machine you control. This makes MiniServ straightforward from an international data transfer perspective, provided you host it within the jurisdiction you intend.

Practical compliance steps

To run MiniServ compliantly, always serve the interface over HTTPS so the session cookie is encrypted in transit, and keep the secure and httpOnly cookie flags enabled. Restrict administrator access by IP where possible, use strong credentials and two factor authentication, and keep Webmin or Usermin updated to receive security fixes. Finally, document who has administrator access and reference the strictly necessary session cookie in your internal records of processing.

GDPR consent category

Other

Websites using MiniServ must obtain user consent under GDPR regulations.

Legal basisLegitimate interest (Art. 6(1)(f) GDPR) and the strictly necessary cookie exemption for securing administrator access
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive

DPIA considerations

MiniServ is self hosted and processes only the data needed to authenticate administrators through a first party session cookie, so a formal Data Protection Impact Assessment is generally not required. Operators should still record administrator access in their internal documentation and apply standard access controls. Because no visitor tracking or third party data sharing takes place, the residual privacy risk is low.

Sample consent text

This site uses a strictly necessary MiniServ session cookie to keep administrators securely signed in, which does not require consent.

Technical details

Tracking methodFirst party session cookie for administrator authentication
Server locationSelf hosted (on the operator own server)

Third-party domains contacted

webmin.com

Cookies placed

NameTypeDurationPurpose
sidStrictly NecessarySessionKeeps an authenticated administrator logged in to the Webmin or Usermin interface for the duration of the session. Issued with the secure and httpOnly flags over HTTPS.
testingStrictly NecessarySessionShort lived cookie used at login to confirm that the administrator browser accepts cookies before establishing the authenticated session.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does MiniServ set?

MiniServ sets a first party session cookie, commonly named sid, when an administrator logs in, and it may use a short lived testing cookie to confirm that the browser accepts cookies. The session cookie holds only an opaque identifier and, over HTTPS, carries the secure and httpOnly flags. No third party or tracking cookies are involved.

Is consent required for the MiniServ session cookie?

No. The session cookie is strictly necessary to provide the secure login that the administrator explicitly requested, so it falls under the Article 5(3) ePrivacy exemption. No cookie banner or prior consent is needed for it. You should still document the cookie in your internal privacy records.

What is the legal basis for processing?

The minimal processing relies on the operator legitimate interest under Article 6(1)(f) GDPR in securing access to its own systems, combined with the strictly necessary cookie exemption under the ePrivacy Directive. Because access is limited to authenticated administrators, the basis is well supported and the risk is low.

Does MiniServ transfer data to third countries?

No. MiniServ is entirely self hosted and does not send personal data to third parties or to servers outside your own infrastructure. Session data never leaves the machine you control, so there is no third country transfer to assess as long as you host it within your intended jurisdiction.

Do I need a DPIA for MiniServ?

Generally no. MiniServ processes only the minimal data needed to authenticate administrators, with no visitor tracking or third party sharing, so a formal Data Protection Impact Assessment is usually not required. You should still record administrator access and apply standard access controls as part of good practice.

How do I implement MiniServ compliantly?

Serve the interface over HTTPS so the session cookie is encrypted in transit, and keep the secure and httpOnly flags enabled. Restrict administrator access by IP where possible, use strong credentials and two factor authentication, and keep Webmin or Usermin updated for security fixes. Document who holds administrator access.

What are the alternatives to MiniServ?

MiniServ is part of Webmin and Usermin, so it is chosen alongside those tools. If you are comparing administration panels, alternatives include Cockpit, Ajenti and Plesk. Each has its own architecture and cookie behaviour, so review the relevant privacy and security characteristics before switching.

Should I update my cookie policy for MiniServ?

If your cookie or privacy documentation covers the administration interface, mention the strictly necessary MiniServ session cookie for transparency, even though it does not require consent. Describe its purpose, that it is first party and self hosted, and that no tracking takes place.