The root password controls a highly privileged server account. Change it only when you administer that server and have an approved recovery route if the new credential does not work.
IN THIS ARTICLE
Prepare for the change
Confirm this is the intended server and that you have root access or equivalent authorized privileges. A reseller password and a cPanel customer password are different credentials. Keep an existing secure administrative session open and confirm access to the provider console before rotation.
01 Change the server root password in WHM
- Open Server Configuration > Change Root Password.
- Generate a long, unique password and save it in an approved password manager. Avoid reusing a customer, billing or mailbox password.
- Enter and confirm the new root password, then select Change Password.
- Use a separate browser session to verify the new WHM login before closing your original session. Test another authorized access path only if it is configured to allow password authentication.
- Update any authorized systems that still use the old credential. Prefer scoped API tokens or SSH keys for suitable integrations rather than distributing the root password.
How do I test the new root password safely?
Confirm that the new WHM login works and the old password no longer authenticates. Review automation or monitoring that may have depended on the changed password. SSH key access is not automatically revoked by changing a password.
If the change does not work
If you lose access, use the provider console or authorized recovery process. Do not repeatedly guess the credential or change firewall and SSH settings blindly. For suspected compromise, review other administrators, keys, tokens and persistence mechanisms; rotating only the root password is not a complete incident response.