Configure Security Policies

For WHM version 11.32

This interface allows you to configure a basic security policy for your cPanel users.

Security Policy Items

This section of the interface allows you to configure 3 options for your security policy.

Password Age

This option allows you to specify the number of days cPanel, webmail, and WHM users are allowed to use the same password. Forcing users to change passwords on a frequent basis will help secure your server.

To specify the number of days users are allowed to use the same password:

  1. Click the Password Age checkbox.
  2. Enter the number of days you wish to specify in the resulting text box.
  3. Click the Save button.

Password Strength

This option allows you to specify the minimum password strength for cPanel, webmail, and WHM users. Requiring strong passwords will help secure your server.

To specify a minimum password strength:

  1. Click the Password Strength checkbox.
  2. Click the link to the Password Strength Configuration page.
  3. Click the Save button.

Limit Logins to Verified IP Addresses

This option allows you to determine whether users can log into their cPanel, webmail, and WHM accounts from unverified IP addresses. You can reach the interface to specify verified IP addresses in the Security Questions feature (Main >> Security Center >> Security Questions >> Manage Access IPs).

To limit logins to verified IP addresses:

  1. Click the Limit logins to verified IP Addresses checkbox.
  2. Click Save.

  • note Note: After you click Save, you will be prompted to set your account's security questions and answers.

Enable Security Policy Extensions

This section of your WHM interface allows you to apply your security policy to XML API requests and DNS cluster requests.

XML API and JSON API requests

Clicking this checkbox applies the Security Policy Items to XML API and JSON API requests. This means that the policies set above are applied to any user attempting to make an XML API or JSON API call.

DNS cluster requests

Clicking this checkbox applies the Security Policy Items to DNS cluster requests. This means that the policies set above are applied to any user attempting to make a DNS cluster request.

Disable Security Questions

The root user can disable security questions via SSH.

To disable security questions, change the value of SecurityPolicy::SourceIPCheck in /var/cpanel/cpanel.config to 0.

Topic revision: r13 - 01 May 2012 - 20:55:58 - Main.RosieArcelay
AllDocumentation/WHMDocs.SecurityPolicy moved from Sandbox.SecurityPolicy on 17 Jun 2010 - 18:17 by Main.JustinSchaefer - put it back
 

Copyright © cPanel 2000–2011.