Go Back   HostGator Peer Support Forums > Public Forums > Suggestions

Notices

Reply
 
Thread Tools
  #1  
Old 01-14-2010, 06:56 AM
BrandonH BrandonH is offline
Hatchling Croc
 
Join Date: Dec 2009
Posts: 5
Default Secure storage of plaintext root password

HostGator TOS requires that a current root password be kept on file for VPS and dedicated servers (which is reasonable). The only way to do this is to submit a ticket with the root password in plaintext. Tickets are fully viewable in the ticket system. The security of all VPS and dedicated servers now unnecessarily depends on the security of the ticket system authentication.

A better solution would be a WHM/cPanel addon or a one way drop box with secure submission.
Reply With Quote
  #2  
Old 01-15-2010, 12:45 AM
GatorNathon's Avatar
GatorNathon GatorNathon is offline
Management Team
 
Join Date: Sep 2006
Posts: 24,844
Default Re: Secure storage of plaintext root password

Quote:
Originally Posted by BrandonH View Post
HostGator TOS requires that a current root password be kept on file for VPS and dedicated servers (which is reasonable). The only way to do this is to submit a ticket with the root password in plaintext. Tickets are fully viewable in the ticket system. The security of all VPS and dedicated servers now unnecessarily depends on the security of the ticket system authentication.

A better solution would be a WHM/cPanel addon or a one way drop box with secure submission.
I believe what you are referring to is this section

12.) Dedicated Servers
HostGator reserves the right to reset the password on a dedicated server if the password on file is not current so that we may do security audits as required by our datacenter. It is the responsibility of the client to ensure that there is a valid email address and current root password on file for their dedicated server on file to prevent downtime from forced password resets.


Basically what this is referring to is if we have to get in to do an investigation and we are intentionally being blocked access we will do what is needed. We do have SSH keys setup to all servers so we normally do not need your password at all in tickets.

This typically will not cause any problems for your normal user it will only cause problems for those abusing our system. It is possible to remove our SSH key and change the password which is not a a big deal but usually the only people who really want to keep us out that bad are doing something they aren't supposed to. For example, if we receive a complaint that one of our servers is sending out tons of spam we must get into it as soon as possible to figure out what is going on.

I also do agree this is a great idea and is something we could implement into our new billing system and I'll see what we can do.
Reply With Quote
  #3  
Old 01-15-2010, 07:54 AM
BrandonH BrandonH is offline
Hatchling Croc
 
Join Date: Dec 2009
Posts: 5
Default Re: Secure storage of plaintext root password

I only recently found the seperate system for VPS billing. You guys are so close to secure root password submission and storage already. The system itself is run over SSL. Only the first few characters of the root password currently on file are displayed. All that's missing is a form to update the password on file.
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Website hacked, how do I update the ROOT mysql password? Fabrice Shared Hosting Support 23 01-21-2008 01:37 PM
How secure is it to e-mail a root password? Freaking Crazy Webhosting 1 05-09-2006 03:45 PM
DB root password deepsignal Shared Hosting Support 5 09-24-2005 08:59 PM

All times are GMT -5. The time now is 04:12 AM.