Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section General Discussion
  • Search

What is the thought behind the default admin and admin_ prefix?

General questions about VestaCP
Post Reply
  • Print view
Advanced search
3 posts • Page 1 of 1
Spythe
Posts: 9
Joined: Wed Jun 21, 2017 7:15 pm

What is the thought behind the default admin and admin_ prefix?
  • Quote

Post by Spythe » Thu Jun 22, 2017 3:07 pm

I was wondering why the default user is called 'admin' and the prefix is 'admin_'. Is there a reason for this? I read that having an additional prefix is a so-called 'security measurement', but 'admin' is almost more common than the name 'John' in America. From that perspective, 'vesta' would be more secure, in my opinion.

So anyone care to clarify it? Just wondering.
Top

ScIT
Support team
Posts: 617
Joined: Mon Feb 23, 2015 4:13 pm

Os: Ubuntu 17x
Web: apache + nginx
Re: What is the thought behind the default admin and admin_ prefix?
  • Quote

Post by ScIT » Fri Jun 23, 2017 8:37 am

The prefix is not rellay a "security-thing", more a management one. Admin is one of the most common ways for default user, that's right. In VestaCP you can't rename or delete this user. If you choose a secure/strong password (what should be a standard of course) there is no security issue in using this user. Brute force attacks will be detected and blocked by fail2ban, so no "problem" in that way.
Top

mehargags
Support team
Posts: 1096
Joined: Sat Sep 06, 2014 9:58 pm
Contact:
Contact mehargags
Website Skype

Os: Debian 8x
Web: apache + nginx
Re: What is the thought behind the default admin and admin_ prefix?
  • Quote

Post by mehargags » Sat Jun 24, 2017 1:41 pm

as ScIT said, if you configure everything properly upto security standards.. it should not be a problem.
Don't use admin account to host any sites.. create a separate user for each site or atleast each group of customers.

However, I do feel the ability to choose "admin" user account's name during VestaCP install would be great... security through obfuscation is a great way and would reduce attack surface and attempt if both username and password are to be guessed.

I had proposed this 3 years back... may be at some point it will be possible for the Devs to include such an option
Top


Post Reply
  • Print view

3 posts • Page 1 of 1

Return to “General Discussion”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

cron

Login  •  Register

I forgot my password