What WHM and cPanel Do When the OS Password Expires
cPanel uses the underlying Linux account for authentication. When the system password reaches its expiration date (as defined in /etc/shadow), the pam_unix module will refuse login and prompt the user to change the password via the terminal or SSH.
By default, the web‑based cPanel login does not show a password‑change prompt when the underlying password has expired. The session is denied with an error similar to "Password has expired". This is because cPanel’s authentication layer does not automatically detect the expiration flag in /etc/shadow for web logins.
To give users a web UI path to update their password after an OS‑level expiration, you must either enable the WHM “Password Expiration” feature (which records an expiration date in the cPanel database) or implement a custom sync that updates /etc/shadow to match the WHM setting.
Synchronizing WHM and /etc/shadow
Below is a practical, safe approach to keep the two systems aligned:
Confirm that the WHM Password Expiration feature is enabled for the accounts you want to manage. If it’s disabled, the script will not apply any expiration.
Create a small PHP or shell script that iterates over all cPanel accounts, reads the expiration date via the UAPI, and applies it to the system user with chage:
#!/usr/bin/env bash
# sync_expiration.sh – one‑time sync of WHM to /etc/shadow
for user in $(uapi --output=json getacctlist | jq -r '.data[].user'); do
exp=$(uapi --output=json passwd | jq -r ".data."$user".expire_date")
if [[ "$exp" != "never" ]]; then
# Convert YYYY-MM-DD to epoch for chage
epoch=$(date -d "$exp" +%s)
chage -E $epoch $user
fi
done
Schedule a nightly cron job to keep the sync up to date:
0 2 * * * /usr/local/cpanel/bin/sync_expiration.sh >> /var/log/sync_expiration.log 2>&1
Verify the alignment:
- Run
chage -l username and confirm the “Password expires” field matches the date shown in WHM.
- Check
/etc/shadow with grep username /etc/shadow to see the EXPIRE field.
- Review
/var/log/cron or the log file you redirected to ensure the job ran successfully.
Key Points to Remember
- cPanel’s web login will deny access if the OS password has expired; it does not prompt for a change.
- Enabling WHM’s Password Expiration feature is the simplest way to give users a web‑based change path.
- If you prefer to keep the OS and WHM in sync automatically, use the API‑driven script or a cron job.
- Always test on a non‑production account first to confirm the behavior before rolling out.
Diagnostic Question
To tailor the recommendation precisely, could you confirm whether the WHM Password Expiration feature is currently enabled for your accounts?