Community Forums
Connect with us on LinkedIn
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Apr 2010
    Posts
    5

    Default Security features to negate desire for separate port for root login

    It would be a great security benefit if we could lock out root access to any IP address but our own LAN. Unfortunately the WHM needs to be accessible on port 2086 & 2087 to everyone including root, which in our minds is a security issue. I imagine a couple if statements in your authentication module tracking what port the user is accessing and whether or not they are trying the root account would be a simple framework for building this feature.

    Thanks,

    Somecallmemike

  2. #2
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by somecallmemike View Post
    It would be a great security benefit if we could lock out root access to any IP address but our own LAN. Unfortunately the WHM needs to be accessible on port 2086 & 2087 to everyone including root, which in our minds is a security issue. I imagine a couple if statements in your authentication module tracking what port the user is accessing and whether or not they are trying the root account would be a simple framework for building this feature.

    Thanks,

    Somecallmemike
    In the next version of cPanel/WHM (11.25.1) we will be introducing functionality we call Security Policy. Part of this is the ability to enable IP validation for logins. This means that if someone attempts to login to root from an unusual IP range (e.g. if you always login via your LAN, now someone is trying to login as root from outside your LAN), they will be prompted to answer several security questions you set up ahead of time. They will need to answer the questions correctly before logging in. These questions are only asked when someone attempts to login to an account (e.g. root) from a range that is not normal for that account to be logging in from.

    Now, let's say you needed to login to your box while at HostingCon (where cPanel will be exhibiting, BTW). You can go through this process of answering the security questions, then when you're back at your desk at work, remove that IP address you logged in from while at HostingCon.

    If I understand your specific situation correctly, this functionality will meet your needs. If so, let me know so I can merge this thread with our existing thread for Security Policy so you can receive updates regarding its implementation. A progress bar summarizing progress of this feature's implementation is available at:

    Software Releases - cPanel Inc.

  3. #3
    cPanel Product Evangelist Infopro's Avatar
    Join Date
    May 2003
    Location
    Pennsylvania
    Posts
    7,892
    cPanel/Enkompass Access Level

    Root Administrator

    Lightbulb Important cPanel/WHM Version Number Designation Change

    Please Note: Important cPanel/WHM Version Number Designation Change

    As of July 28, 2010 the cPanel/WHM version number designations have been officially changed.

    Version 11.25.1 is now designated 11.28 and version 11.25.2 is now designated 11.30.

    These new changes were explained in some detail recently at the July 2010 - Quarterly Road map - Webinar direct from cPanel's PodCast Studio in Houston, Texas with speakers David Grega and Mario Rodriguez.

    An official press release about these changes is forthcoming and can be accessed at this link as soon as it's made available to the Forum Team:
    Important cPanel/WHM Version Number Designation Change (To be updated)

    This post serves to update users who are subscribed to threads (where this message is posted) looking forward to upcoming enhancements in future versions of cPanel.

  4. #4
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default re: Security features to negate desire for separate port for root login

    Quote Originally Posted by cPanelDavidG View Post
    In the next version of cPanel/WHM (11.25.1) we will be introducing functionality we call Security Policy. Part of this is the ability to enable IP validation for logins. This means that if someone attempts to login to root from an unusual IP range (e.g. if you always login via your LAN, now someone is trying to login as root from outside your LAN), they will be prompted to answer several security questions you set up ahead of time. They will need to answer the questions correctly before logging in. These questions are only asked when someone attempts to login to an account (e.g. root) from a range that is not normal for that account to be logging in from.

    Now, let's say you needed to login to your box while at HostingCon (where cPanel will be exhibiting, BTW). You can go through this process of answering the security questions, then when you're back at your desk at work, remove that IP address you logged in from while at HostingCon.

    If I understand your specific situation correctly, this functionality will meet your needs. If so, let me know so I can merge this thread with our existing thread for Security Policy so you can receive updates regarding its implementation. A progress bar summarizing progress of this feature's implementation is available at:

    Software Releases - cPanel Inc.
    This functionality is now propagating with version 11.28.

  5. #5
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    11,189
    cPanel/Enkompass Access Level

    Root Administrator

    Default Re: Security features to negate desire for separate port for root login

    This functionality is now available in all update tiers of cPanel&WHM. I am now closing and archiving this request thread.

Similar Threads & Tags
Similar threads

  1. Filed with Developers Limit WHM root access (and other accounts) only to allowed IPs [Case 53377]
    By SNET1 in forum Feature Requests for cPanel/WHM
    Replies: 42
    Last Post: 05-09-2012, 06:25 AM
  2. [Case 46853] Not allow root login on cPanel port 2083
    By monarobase in forum Archived Feature Requests
    Replies: 9
    Last Post: 08-18-2011, 02:25 PM
  3. How to share the root administrator account with separate passwords
    By doncolton in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 02-28-2007, 09:21 PM
  4. Making CPanel login separate from all-access ftp login?
    By whataguy in forum New User Questions
    Replies: 0
    Last Post: 04-14-2005, 10:36 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube