Changing the server root password in WHM

The root password controls a highly privileged server account. Change it only when you administer that server and have an approved recovery route if the new credential does not work.

Prepare for the change

Confirm this is the intended server and that you have root access or equivalent authorized privileges. A reseller password and a cPanel customer password are different credentials. Keep an existing secure administrative session open and confirm access to the provider console before rotation.

01 Change the server root password in WHM

  1. Open Server Configuration > Change Root Password.
  2. Generate a long, unique password and save it in an approved password manager. Avoid reusing a customer, billing or mailbox password.
  3. Enter and confirm the new root password, then select Change Password.
  4. Use a separate browser session to verify the new WHM login before closing your original session. Test another authorized access path only if it is configured to allow password authentication.
  5. Update any authorized systems that still use the old credential. Prefer scoped API tokens or SSH keys for suitable integrations rather than distributing the root password.

How do I test the new root password safely?

Confirm that the new WHM login works and the old password no longer authenticates. Review automation or monitoring that may have depended on the changed password. SSH key access is not automatically revoked by changing a password.

If the change does not work

If you lose access, use the provider console or authorized recovery process. Do not repeatedly guess the credential or change firewall and SSH settings blindly. For suspected compromise, review other administrators, keys, tokens and persistence mechanisms; rotating only the root password is not a complete incident response.

Sources and further reading

  • 0 Users Found This Useful
  • cpanel-whm, servers
Was this answer helpful?

Related Articles

Setting the default nameservers in WHM

The WHM default nameservers provide nameserver values for account provisioning on the server....

Using WHM disabled features for server-wide restrictions

The special disabled feature list is a server-wide restriction mechanism. It overrides ordinary...

Setting the server time and timezone in WHM

Accurate server time matters for logs, scheduled jobs, authentication and licensing. A timezone...

Setting up private nameservers for a WHM reseller

Private nameservers such as ns1.example.com and ns2.example.com let customers use nameservers...

Creating a feature list in WHM

A feature list controls which cPanel tools a package exposes. Use it to provide a purposeful...