[{"data":1,"prerenderedAt":28},["ShallowReactive",2],{"doc-en-change-root-password-vps":3},{"path":4,"slug":5,"title":6,"description":7,"category":8,"subcategory":9,"icon":10,"date":11,"author":12,"order":13,"image":14,"tags":15,"keywords":19,"docGroup":25,"docGroupIcon":25,"link_fr":26,"bodyHtml":27},"\u002Fdocs\u002Fen\u002Fvps\u002Fvps-linux\u002Fchange-root-password-vps","change-root-password-vps","How to Change Your VPS's Root Password","Change your Winheberg VPS's root password from your client area or via SSH with the passwd command.","vps","vps-linux","tabler:file-text","2026-07-24","Winheberg",5,"\u002Fstatics\u002Fimages\u002Fdocs\u002Fen\u002Fvps-linux\u002Fchange-root-password-vps.webp",[8,16,17,18],"password","security","getting started",[20,21,22,23,24],"change vps root password","passwd command linux","change password client area","secure vps","strong root password","","\u002Fdocs\u002Fvps-linux\u002Fchanger-mot-de-passe-root-vps","\u003Ch2>Context\u003C\u002Fh2>\n\u003Cp>You just received your \u003Cstrong>Linux VPS\u003C\u002Fstrong> at Winheberg with a root password automatically generated by our system? The very first recommended step after connecting is to \u003Cstrong>change this password\u003C\u002Fstrong> to one only you know. This prevents anyone who may have intercepted the delivery email from accessing your server.\u003C\u002Fp>\n\u003Cp>Two methods are available, from your client area without going through SSH, or directly from the command line on your server. This guide covers both, and works on every distribution we offer, namely Debian 11\u002F12\u002F13, Ubuntu 23.10\u002F24.04\u002F25.04, AlmaLinux 9\u002F10, Rocky Linux 9\u002F10, Fedora 41\u002F42, and Alpine Linux 3.22.\u003C\u002Fp>\n\u003Ch2>Why change the root password?\u003C\u002Fh2>\n\u003Cp>Several reasons make this step important. First, the initial password was sent to you by \u003Cstrong>email\u003C\u002Fstrong>, a channel that can be intercepted or accessed by others with access to your inbox. Second, an automatically generated password isn&#39;t always \u003Cstrong>easy to memorize\u003C\u002Fstrong>, which often leads to writing it down in plain text somewhere, which isn&#39;t ideal. Finally, by choosing a \u003Cstrong>strong, unique\u003C\u002Fstrong> password yourself, you stay in control of your server&#39;s security.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-note\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cline x1=\"12\" y1=\"16\" x2=\"12\" y2=\"12\"\u002F>\u003Cline x1=\"12\" y1=\"8\" x2=\"12.01\" y2=\"8\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>If you plan to set up \u003Cstrong>SSH key authentication\u003C\u002Fstrong> (recommended), changing the password is still useful since it will be asked for \u003Ccode>sudo\u003C\u002Fcode> commands or to recover access through the rescue console.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>Method 1. From your client area\u003C\u002Fh2>\n\u003Cp>This is the simplest method, it requires no SSH connection at all.\u003C\u002Fp>\n\u003Col>\n\u003Cli>Log in to your \u003Cstrong>Winheberg client area\u003C\u002Fstrong>\u003C\u002Fli>\n\u003Cli>Go to the relevant VPS&#39;s management page\u003C\u002Fli>\n\u003Cli>Find the \u003Cstrong>Change Password\u003C\u002Fstrong> action\u003C\u002Fli>\n\u003Cli>Follow the on-screen instructions to set your new root password\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>The new password is applied directly by our system, there&#39;s nothing else for you to do on your end.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-tip\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cpath d=\"M12 16v-4\"\u002F>\u003Cpath d=\"M12 8h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>This method is especially handy if you&#39;re locked out of your server (forgotten password, SSH connection not working) since it doesn&#39;t depend on a working SSH access.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>Method 2. Via SSH with the passwd command\u003C\u002Fh2>\n\u003Cp>If you&#39;d rather change the password directly from the server, or if you also need to change another user&#39;s password, here&#39;s the command-line procedure.\u003C\u002Fp>\n\u003Ch3>1. Connect to your VPS via SSH\u003C\u002Fh3>\n\u003Cp>Connect to your server via SSH with the initial password received by email.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">ssh root@YOUR_VPS_IP\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cdiv class=\"markdown-alert markdown-alert-note\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cline x1=\"12\" y1=\"16\" x2=\"12\" y2=\"12\"\u002F>\u003Cline x1=\"12\" y1=\"8\" x2=\"12.01\" y2=\"8\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>Your server&#39;s IP address was sent to you in the delivery email from our team when you ordered, or in the IP Address section of your client area. Replace \u003Ccode>YOUR_VPS_IP\u003C\u002Fcode> with that address (for example \u003Ccode>ssh root@51.158.xx.xx\u003C\u002Fcode>).\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch3>2. Change the root password\u003C\u002Fh3>\n\u003Cp>Once connected, simply run the following command.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">passwd\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>The system will ask you to enter the \u003Cstrong>new password\u003C\u002Fstrong> twice.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>New password:\nRetype new password:\npasswd: password updated successfully\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cdiv class=\"markdown-alert markdown-alert-warning\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Cpath d=\"M10.29 3.86L1.82 18a2 2 0 0 0 1.71 3h16.94a2 2 0 0 0 1.71-3L13.71 3.86a2 2 0 0 0-3.42 0z\"\u002F>\u003Cline x1=\"12\" y1=\"9\" x2=\"12\" y2=\"13\"\u002F>\u003Cline x1=\"12\" y1=\"17\" x2=\"12.01\" y2=\"17\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>Nothing shows up on screen while you type your password. That&#39;s normal, it&#39;s a protection against prying eyes. Type your password then press Enter.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Cp>If both entries match, the password is changed immediately. No reconnection is needed for the change to take effect.\u003C\u002Fp>\n\u003Ch3>3. Change another user&#39;s password\u003C\u002Fh3>\n\u003Cp>The \u003Ccode>passwd\u003C\u002Fcode> command can also change the password of a \u003Cstrong>user other than\u003C\u002Fstrong> root. Just specify their name at the end.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">passwd username\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>You need to be logged in as root (or use \u003Ccode>sudo\u003C\u002Fcode>) to change another account&#39;s password. This command is useful, for example, if you created a secondary user and want to set or reset their password.\u003C\u002Fp>\n\u003Ch2>Choosing a strong password\u003C\u002Fh2>\n\u003Cp>A root password is your \u003Cstrong>server&#39;s key\u003C\u002Fstrong>. It should be as strong as possible. To be effective, it should contain \u003Cstrong>at least 16 characters\u003C\u002Fstrong>, mix \u003Cstrong>uppercase, lowercase, digits, and special characters\u003C\u002Fstrong>, and not resemble any \u003Cstrong>dictionary word\u003C\u002Fstrong> or personal information (birth date, first name, etc.).\u003C\u002Fp>\n\u003Cp>Examples of strong passwords.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>g7$Tk!Bn92#vXr@P\nM0nVps-Secur1se!2026\nTxX9!pq@2KvR^bF7\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>To avoid having to memorize complex passwords, the ideal solution is to use a \u003Cstrong>password manager\u003C\u002Fstrong> like Bitwarden, Vaultwarden, KeePass, or 1Password. You&#39;ll only need to remember one master password, and the manager will store all the others securely.\u003C\u002Fp>\n\u003Cdiv class=\"markdown-alert markdown-alert-tip\">\u003Cspan class=\"alert-icon\">\u003Csvg xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" width=\"16\" height=\"16\" viewBox=\"0 0 24 24\" fill=\"none\" stroke=\"currentColor\" stroke-width=\"2\" stroke-linecap=\"round\" stroke-linejoin=\"round\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"10\"\u002F>\u003Cpath d=\"M12 16v-4\"\u002F>\u003Cpath d=\"M12 8h.01\"\u002F>\u003C\u002Fsvg>\u003C\u002Fspan>\u003Cdiv class=\"markdown-alert-body\">\u003Cp>If you really want to secure your VPS, disable password-based login entirely and switch to \u003Cstrong>SSH key authentication\u003C\u002Fstrong>. Our guide on securing a VPS covers the full procedure.\u003C\u002Fp>\n\u003C\u002Fdiv>\u003C\u002Fdiv>\n\u003Ch2>If you run into trouble\u003C\u002Fh2>\n\u003Cp>Here are the most common errors you might run into.\u003C\u002Fp>\n\u003Ch3>❌ BAD PASSWORD, The password is too short\u003C\u002Fh3>\n\u003Cp>Your password is too short or too simple. Add more characters and mix uppercase, digits, and special characters. As root, you can force a weak password, but it&#39;s strongly discouraged.\u003C\u002Fp>\n\u003Ch3>❌ passwd, Authentication token manipulation error\u003C\u002Fh3>\n\u003Cp>A rare error indicating a system file issue. Check that \u003Ccode>\u002Fetc\u002Fpasswd\u003C\u002Fcode> and \u003Ccode>\u002Fetc\u002Fshadow\u003C\u002Fcode> aren&#39;t corrupted, and that your disk isn&#39;t full with \u003Ccode>df -h\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Ch3>❌ I forgot my new password\u003C\u002Fh3>\n\u003Cp>Don&#39;t panic. Use the \u003Cstrong>Change Password\u003C\u002Fstrong> action from your client area (Method 1), which doesn&#39;t require SSH access. You can also go through your VPS&#39;s rescue console (rescue mode \u002F KVM console) and use \u003Ccode>passwd\u003C\u002Fcode> to set a new password. If you&#39;re not sure how, contact our support.\u003C\u002Fp>\n\u003Ch3>❌ On Alpine, the passwd command isn&#39;t found\u003C\u002Fh3>\n\u003Cp>This is very rare, but if Alpine is installed in a minimal version, the \u003Ccode>shadow\u003C\u002Fcode> package may not be present. Install it with this command.\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-bash\">apk add shadow\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch2>Need help?\u003C\u002Fh2>\n\u003Cp>If you run into an issue changing your root password, our team is here. Open a ticket in the \u003Cstrong>Technical\u003C\u002Fstrong> department from your client area and fill in the \u003Cstrong>Related Product\u003C\u002Fstrong> field with the VPS in question.\u003C\u002Fp>\n\u003Cp>Your VPS is now protected with a password only you know 🔐\u003C\u002Fp>\n",1788993143929]