Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 8 of 8
  1. #1
    Member
    Join Date
    Mar 2005
    Posts
    6

    Unhappy Root Password Problem

    I have just as a security measure changed root password. I have the password written down and the program I generated the password from says I am entering the correct password but it will not let me login as root either in whm or ssh...

    Please can anyone help.

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    The only thing you can do is to contact your datacenter and have them connect via the console and have them reset your root password for you, it cannot be done remotely.

    I'd then advise that you research using key authentication for SSH login to the root account to avoid that problem in the future.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  3. #3
    Member
    Join Date
    Mar 2005
    Posts
    6

    Default Thanks For That

    Hi Chirpy

    Thanks for your help...I am seeing if the datacenter can do that for me as we speak..

    Gary

  4. #4
    Member
    Join Date
    Apr 2003
    Posts
    174
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by chirpy
    I'd then advise that you research using key authentication for SSH login to the root account to avoid that problem in the future.
    In my opinion it would be better to disable remote root login altogether, and instead use sudo so the root password is never needed.

  5. #5
    Member sawbuck's Avatar
    Join Date
    Jan 2004
    Posts
    1,313
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by Odhinn
    In my opinion it would be better to disable remote root login altogether, and instead use sudo so the root password is never needed.
    The advantage of not having to su to root all the time, by allowing a single IP to connect to a second SSH daemon using key authentication on an uncommon port, makes many server tasks a whole lot easier.

  6. #6
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    Indeed. Key authentication is leagues more secure than any password based system, especially sudo. Once you start allowing non-priv users to do priv operations you're simply opening yourself up for more trouble. With key authentication enabled and password access disabled you're only realistic next level of access security would be to use port knocking with key authentication.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  7. #7
    Member
    Join Date
    Apr 2003
    Posts
    174
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    My way of thinking is that if it is not possible to login directly as root, and only key-based authentication is allowed, then an attacker would have to guess the username of the account you use as an admin, crack your public key and crack your password in order to authenticate with sudo. To me this seems more secure than simply requiring a key to login as root, even if you do have a second daemon running (it would not take long for a determined attacker to find it, no matter which port you put it on).

  8. #8
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    I wouldn't disagree with that, on the proviso that the alternative account is not a cPanel account Having said that, cracking an SSH key if you only have root key authentication enabled would be no mean feat.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

Similar Threads & Tags
Similar threads

  1. possible to change WHM root indepdently from server root password
    By jfall123 in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 01-12-2011, 11:53 AM
  2. Root password change problem !
    By zonereseau in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 04-11-2008, 04:30 PM
  3. Mysql root password at root directory ?
    By sh4ka in forum cPanel and WHM Discussions
    Replies: 11
    Last Post: 09-23-2005, 03:43 PM
  4. cpanel bug / Get root access with root password
    By majidnt in forum cPanel and WHM Discussions
    Replies: 19
    Last Post: 08-24-2005, 11:12 AM
  5. URGENT - lost FTP password for customer, root password not w
    By RandyL712 in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 09-20-2002, 12:42 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube