Skip to main content

Security Advisor Check Questions

Comments

2 comments

  • httpdocs
    All is right. Of course, with the current settings, there is no particular security issue for you. In my opinion, just setting up "Change SSH Port" and "PermitRootLogin " and a secure password of more than 16 characters is enough. :)
    0
  • cPanelLauren
    Hi @flagkakis Please keep in mind that the security advisor provides suggestions based on best practices for common webhosting environments and they aren't necessarily optimal for all uses.
    1. The Jail Apache option is not available to me (am pretty sure am missing something here),

    The Jail apache option is only available if the following conditions are met which are detailed in tweak settings: If mod_ruid2 is compiled in via EasyApache, mod_ruid2 is enabled, and a user has their shell set to jailshell or noshell, enabling this option will chroot() a user's Apache Virtual Host into the cPanel" jailshell environment. Each user will require 14 bind mounts. While modern Linux supports a very large number of bind mounts, many processes read /proc/mounts. Reading /proc/mounts can be quite expensive when it becomes large.
    2. SSH Password authentication -> I keep on changing it to off and later on it comes back on, I have researched the web and pretty much could not find anything,

    When you disable password authorization at WHM>>Security Center>>SSH Password Authorization Tweak what is displayed on the screen?
    3. SSH direct root logins, I have been changing that and pass the advisor's checks but then it goes right back to on, not sure why this is happening I can't find any info,

    For direct root logins to be disabled you'd need to make manual edits as described in the Security Advisor: Manually edit /etc/ssh/sshd_config and change PermitRootLogin to "without-password" or "no", then restart SSH in the "
    0

Please sign in to leave a comment.