Changing your cPanel or reseller account password is simple and can be done through the Password Modification interface in your control panel. If you've lost or forgotten your password, administrators can set a new one without needing the original password. This guide walks you through the complete process of updating your account credentials securely.
Understanding Password Modification
The Password Modification interface allows you to change passwords for both reseller and cPanel accounts. This becomes particularly useful when passwords are lost, forgotten, or compromised. As an administrator, you can reset passwords for any account under your management without requiring the old password.
Important: You cannot retrieve existing passwords. If a password is lost or forgotten, you must create a completely new password. For security reasons, passwords are encrypted and cannot be recovered in their original form.
How to Change Your Account Password
Follow these steps to update your account password:
- Select the account for which you want to change the password from the available options.
- Enter your new password in the password field, then confirm it by typing it again in the confirmation field.
- If the option is available, select Synchronize MySQL password to use the same password for both your MySQL database and cPanel account. This option only appears if the .my.cnf file exists in the /home/USERNAME directory.
- Select Enable Digest Authentication if you need to access Web Disk through unencrypted connections. This is especially important for users on Windows Vista, Windows 7, or Windows 8 who don't have an SSL certificate signed by a recognized certificate authority.
- Click Change Password to save your new credentials.
Creating a Secure Password
Security is critical when setting a new password. A strong password protects your hosting account, email, databases, and website files from unauthorized access.
Your password should meet these criteria:
- Avoid dictionary words or common phrases
- Include a mix of uppercase and lowercase letters
- Incorporate numbers throughout the password
- Use special symbols like !, @, #, $, or %
- Make it at least 12 characters long
- Avoid personal information like birthdays or names
Consider using a password manager to generate and store complex passwords securely. This ensures each account has a unique, strong password without the burden of remembering them all.
MySQL Password Synchronization
When you change your cPanel password, you have the option to synchronize it with your MySQL database password. This means both your control panel and database will use the same credentials, making management simpler.
The synchronization option appears automatically if your account has the .my.cnf configuration file in your home directory. If you don't see this option, the file may not exist, or your account may not have MySQL databases configured.
Keep in mind that if you choose not to synchronize, you'll need to manage separate passwords for cPanel and MySQL, which requires more careful tracking but can provide an extra layer of security.
Digest Authentication for Web Disk Access
Digest authentication enables you to access Web Disk through clear text or unencrypted connections. While this is less secure than encrypted connections, it's sometimes necessary for compatibility with older systems or specific Windows versions.
Enable this option if you're using Windows Vista, Windows 7, or Windows 8 and don't have a properly signed SSL certificate. Without digest authentication enabled, these systems may have difficulty connecting to Web Disk.
For better security, we recommend obtaining a valid SSL certificate rather than relying on digest authentication for unencrypted connections.
Frequently Asked Questions
Can I recover my old password instead of creating a new one?
No, passwords cannot be retrieved or recovered. For security reasons, passwords are stored in encrypted form and cannot be converted back to plain text. You must always create a new password if the current one is lost or forgotten.
What happens to my email and FTP access when I change my cPanel password?
Changing your main cPanel password does not affect individual email accounts or FTP accounts you've created. Those accounts have their own separate passwords. However, if you use your cPanel credentials for FTP (the main account), you'll need to update your FTP client with the new password.
Should I use the same password for cPanel and MySQL?
Using the same password (synchronizing) is convenient and reduces the number of passwords to remember. However, for maximum security, some administrators prefer to use different passwords for different services. Choose the approach that best balances convenience and security for your needs.
How often should I change my password?
While regular password changes were once standard practice, current security best practices recommend changing passwords only when they may have been compromised or when you suspect unauthorized access. Focus instead on using strong, unique passwords and enabling two-factor authentication when available.
If you need assistance with password management or have questions about your OBHost account security, our support team is available 24/7. Visit our contact page or email support@obhost.org for help.