WHM and Linux System User Password Expiration Synchronization
25K reputation · 24 Jan 2020, 04:43 UTC
System User Authentication and cPanel Integration
cPanel relies on the underlying Linux system user accounts for authentication. While WHM provides administrative tools to manage these accounts, there is a functional boundary between the cPanel interface and the system-level password aging policies defined in /etc/shadow.
When a system administrator implements a password expiration policy at the OS level to enforce security compliance, it is unclear how the cPanel login interface handles the transition when a password expires. Specifically, the behavior of the web-based authentication layer during the "grace period" or upon full expiration may differ from the standard SSH terminal experience.
Given a standard cPanel/WHM installation on a supported Linux distribution, what is the expected behavior when a system user's password expires according to the OS policy? Does the cPanel interface trigger a password change prompt, or does it simply deny access without providing a mechanism for the user to update their credentials via the web UI?