cPFence
I'll drop a ticket, but my issue is solved already.
The point was that the default rules, which should not be edited, give the error message. And adding rules manually as per the knowledge base, gives the same errors (and doesn't actually whitelist them).
SecRule REQUEST_HEADERS:Host "@streq example.com" "id:6002,phase:1,pass,nolog,ctl:RuleRemoveById=200007,225170,200002,210230"
This rule would only whitelist 2000007 and throw an error in openlitespeed