Hi my server as just updated to the new WHM 11.40.0 and i have CENTOS 6.4 STANDARD Installed, but when i check the cPanel Security Advisor i get these messages below and before i change anything i need to know if it will break any customers accounts ? and just wanted to know if anyone could give me some info on them please.
Apache vhosts are not segmented or chroot()ed.
Enable “Jail Apache” in the “Tweak Settings” area, and change users to jailshell in the “Manage Shell Access” area. Consider a more robust solution by using “CageFS on CloudLinux”
Frontpage is installed
Rebuild using “EasyApache” without Frontpage selected, then uninstall the Frontpage RPM (rpm -e frontpage)
Trivially weak passwords are permitted.
Configure Password Strength requirements in the “Password Strength Configuration” area
SSH password authentication is enabled.
Disable SSH password authentication in the “SSH Password Authorization Tweak” area
SSH direct root logins are permitted.
Manually edit /etc/ssh/sshd_config and change PermitRootLogin to “no”, then restart SSH in the “Restart SSH” area
Apache is not being queried to determine the actual sender when mail originates from the “nobody” pseudo-user.
Enable “Query Apache server status to determine the sender of email sent from processes running as nobody” in the “Exim Configuration Manager” area's “Basic Editor”
EasyApache3 has updates available.
EasyApache3 needs to be run periodically to update Apache, PHP and other public server functionality to the latest versions. Updates to EasyApache3 often fix security vulnernabilities in this software.
Users running outside of the jail: web and ukwe.
Change these users to jailshell or noshell in the “Manage Shell Access” area.
Apache vhosts are not segmented or chroot()ed.
Enable “Jail Apache” in the “Tweak Settings” area, and change users to jailshell in the “Manage Shell Access” area. Consider a more robust solution by using “CageFS on CloudLinux”
Frontpage is installed
Rebuild using “EasyApache” without Frontpage selected, then uninstall the Frontpage RPM (rpm -e frontpage)
Trivially weak passwords are permitted.
Configure Password Strength requirements in the “Password Strength Configuration” area
SSH password authentication is enabled.
Disable SSH password authentication in the “SSH Password Authorization Tweak” area
SSH direct root logins are permitted.
Manually edit /etc/ssh/sshd_config and change PermitRootLogin to “no”, then restart SSH in the “Restart SSH” area
Apache is not being queried to determine the actual sender when mail originates from the “nobody” pseudo-user.
Enable “Query Apache server status to determine the sender of email sent from processes running as nobody” in the “Exim Configuration Manager” area's “Basic Editor”
EasyApache3 has updates available.
EasyApache3 needs to be run periodically to update Apache, PHP and other public server functionality to the latest versions. Updates to EasyApache3 often fix security vulnernabilities in this software.
Users running outside of the jail: web and ukwe.
Change these users to jailshell or noshell in the “Manage Shell Access” area.