Accounts and Services

How to Distinguish Control Panel Passwords from the System root Password

Compiled by the VPSMap Editorial Team · Updated 2026-09-26 · 15-minute read · Plain-Text Version

One of the most common problems beginners encounter when managing a VPS is, “I just changed the password, but the terminal still says Permission denied”. This confusion usually comes from mixing up the different authentication layers in cloud infrastructure.

A cloud server does not have just one global password; instead, its access layers from outside to inside are divided intoAccount Layer (Billing/Client Portal)、Instance Control Layer (Control Panel)and Operating system 内核层(Linux Guest OS). Providers such as BandwagonHost and DMIT differ significantly in panel architecture and security baselines. BandwagonHost uses a separate KiwiVM panel and multiple password systems, while DMIT's images default to key authentication and disable remote root password login.

Understanding each password's scope and change procedure is fundamental to server security and reliable operations.


Core Authentication Layers and Comparison of Permissions#

To avoid changing the wrong password, first understand the scope and control permissions of these four credential types:

凭据 Type 所属管理层级Authentication ChannelScope of ImpactTypical Usage Scenarios
Client Area PasswordProvider Billing / Membership SystemProvider's Official WebsiteAccount Permissions, Adding Funds, Service Provisioning/Termination, and Ticket SupportManage renewals, change plans, and submit technical support tickets
Separate Control Panel PasswordUnderlying Host Control PlaneKiwiVM / Proprietary Management PanelStart/Stop Instances, Snapshots, OS Resets, ISO Mounting, and Data Center MigrationManage VPS Hardware Status Directly Without Logging into the Official Website Each Time
Linux root PasswordGuest OS Inside the Virtual MachineSSH Terminal, Local TTY ConsoleSystem Kernel Privileges, Package Management, Service Configuration, and Data Read/Write编译安装软件、修改 Linux 系统配置文件
Emergency Console CredentialsVirtualization-Layer VNC / TTYWeb Terminal Embedded in the PanelConnects Directly to the System Terminal, Bypassing External Networking and the SSH Daemon误设防火墙断网、SSH 配置损坏时的应急抢修

[!IMPORTANT] 权限单向性原则: a higher-level panel can directly overwrite lower-level passwords through the virtualization layer, such as forcibly resetting the system root password in the control panel. However, lower-level system privileges can never alter control panel or client area passwords in the reverse direction.


BandwagonHost: KiwiVM's Three-Way Separation Architecture#

BandwagonHost's management system is distinctive. It separates not only the client area and system root access, but also an intermediate, fully featured independent panel, KiwiVM. Users typically manage three completely independent sets of credentials.

1. Client Area Password and KiwiVM Single Sign-On (SSO)#

  • Positioning:用于登录 BandwagonHost 主站后台。
  • 关联机制: Under “Services -> My Services,” click “KiwiVM Control Panel.” The system uses a dynamic Token to sign you into KiwiVM automatically through single sign-on,No control panel password is required at this point. This leads many users to overlook the existence of KiwiVM's separate password.

2. Separate KiwiVM Panel Password (KiwiVM Password)#

  • Positioning: Used to connect directly through https://kiwivm.it7.net or the server IP to access the control panel.
  • Configuration Method:在 KiwiVM 左侧导航栏找到 KiwiVM password modification, enter the new password, and save.
  • Use Cases: If you need to give collaborators permission to start, stop, or reinstall a server while keeping your billing, financial information, and other servers private, simply provide that server's IP and separate KiwiVM password.

3. Linux System root Password#

  • Positioning: superuser privileges within the Linux operating system.
  • Reset Path in the Panel:KiwiVM 左侧导航的 Root password modification。
  • Key Operating Points:
    • 面板 Reset root 密码会在底层触发脚本挂载或离线覆写 /etc/shadow file.
    • Passwords generated by BandwagonHost are usually strong random strings. Copy and save them in a password manager immediately.
    • Reset the root Passwordwill never change KiwiVM's own panel login password.
  • Nonstandard SSH Port Warning: During initialization, BandwagonHost does not use standard port 22 by default; instead, it uses Main Controls page to specify a random high-numbered port (such as 28475). If SSH reports connection refused, check the port number instead of repeatedly assuming the password is wrong.

DMIT: A Modern Cloud Control Panel and Key-First Authentication#

DMIT's console differs significantly from BandwagonHost's. DMIT integrates resource control into a unified client console and strongly favors industrial-grade key-based login standards in its security policy.

1. Unified Panel and Access Credential Management#

在 DMIT 的“My Services”进入 instance 详情后,核心控制权集中在 Access 选项卡下:

  • Password Reset: Set a new instance password directly in the Access interface.
  • How Changes Take Effect (Critical): After passwords or SSH keys are changed in the DMIT panel, the platform generally relies on Cloud-init or an underlying Agent to inject the changes.You Must Perform a “Reboot” (Hard / Panel Reboot) as Instructed by the Panel Before the Changes Are Written into the System Image. Running only inside the operating system reboot commands may sometimes fail to retrieve metadata correctly.

2. Remote root Password Login Disabled by Default#

To prevent automated brute-force attacks, DMIT's official system templates enforce a strict security baseline by default:

  • SSH Key Preferred: The provider strongly recommends using the panel's SSH Keys module to import the public key in advance and link it directly during provisioning or reinstallation.
  • Password Login Restricted: Even after resetting the password in Access, some official DMIT images internally have /etc/ssh/sshd_config may be preset to PermitRootLogin prohibit-password. This means youCannot Authenticate Directly over Remote SSH Using the root Password,密码仅供网页端应急控制台(Web Console)验证使用。

3. Web Console Emergency Access#

When access is lost because of incorrect network settings, accidental firewall blocks, or a damaged SSH configuration:

  • Log in to the DMIT instance page and click Console(VNC / Serial Console)。
  • 控制台模拟的是显示器与物理键盘直连。此时输入的正是 Operating system 的真实用户名(root) and the password reset and activated through Access.
  • Resume normal network connections only after troubleshooting through the console and confirming that SSH is working.

Manual Changes Inside the System versus Control Panel Resets#

There are two common ways to change the system's internal root password, with very different use cases and underlying behavior:

Commands / Configuration
+-------------------------------------------------------------------+
| 场景 A: 尚能通过 SSH 密钥或现有密码登录                           |
|         --> 使用终端原生命令 `passwd` (最快、最安全、无需重启)      |
+-------------------------------------------------------------------+

+-------------------------------------------------------------------+
| 场景 B: 密码遗忘、密钥丢失或 SSH 守护进程瘫痪                     |
|         --> 进入提供商控制面板 (KiwiVM / DMIT Access) 强制重置      |
|         --> 依赖虚拟化底层修改系统文件,通常需要关机或重启实例     |
+-------------------------------------------------------------------+

方式一:终端正常在线修改(推荐)#

If you can currently log into the system (for example, as a regular user or with an existing key):

bash
# 若当前已是 root 用户,直接修改自身密码
passwd

# 若当前是具有 sudo 权限的普通管理员用户(如 admin / debian / ubuntu)
sudo passwd root

[!TIP] When entering a password in a Linux terminal, the screen normally shows no characters, including asterisks. This is a standard security feature. Type the password, press Enter, then enter it again to confirm.

Method Two: Offline / Forced Reset Through the Panel#

Use the panel's reset feature only when you have completely lost the ability to authenticate to the system:

  1. BandwagonHost: go to KiwiVM -> Root password modification -> Click Reset -> Obtain the randomly generated password -> Log in over SSH using the new password and dedicated port.
  2. DMIT: go to Product Management -> Access -> Reset Root 密码 -> Click Restart/Reboot in the Panel to Restart the Instance -> Wait until the instance status becomes Active, then try connecting.

Troubleshooting Common Login Failures#

When the terminal returns an error, troubleshoot step by step using the logic below instead of repeatedly changing unrelated passwords in a panic:

mermaid
flowchart TD
    Start["连接服务器失败"] --> Step1{"终端报什么错?"}
    
    Step1 -->|"Connection refused / Timed out"| NetCheck["排查网络与端口<br>1. 检查面板实例是否处于 Running<br>2. 搬瓦工:核对 Main Controls 的自定义端口<br>3. 检查本地网络或机房 IP 连通状态"]
    
    Step1 -->|"Permission denied (publickey)"| KeyCheck["服务器仅接受密钥认证<br>1. 检查本地是否配置了私钥<br>2. DMIT:通过 Web Console 登录系统检查 sshd 配置<br>3. 在面板重新关联公钥并重启实例"]
    
    Step1 -->|"Permission denied (password)"| PassCheck{"确认密码修改生效了吗?"}
    
    PassCheck -->|"在面板改了 root 密码"| P1["1. DMIT 是否执行了面板重启?<br>2. sshd 是否禁用了 PasswordAuthentication?<br>3. 是否误将 KiwiVM 面板密码当作 root 密码?"]
    PassCheck -->|"在服务商官网改了登录密码"| P2["重大误区:<br>官网账户密码无法改变 Linux 内部 root 密码!<br>需前往面板针对实例进行重置。"]

Common Troubleshooting Scenarios at a Glance#

Error SymptomsIdentify the Root CauseCorrect Resolution
Permission denied (publickey,password)密码错误,或 SSH 服务禁止了当前用户的密码认证通道。1. Log into the Provider's Web Console to View /etc/ssh/sshd_config in PasswordAuthentication 是否为 yes。
2. Check the PAM Authentication Lockout Status.
Connection refusedThe port is incorrect, or the operating system's SSHD daemon has crashed.1. Check Whether the SSH Port in BandwagonHost KiwiVM Has Changed.
2. Log In Through the Panel Console and Run systemctl status sshd Check the service status.
Web Console Login Works, but Remote SSH Rejects the PasswordSecurity hardening is enabled by default in the image, allowing password login only through the local terminal.Edit /etc/ssh/sshd_config, adjust PermitRootLogin yes and PasswordAuthentication yes and restart the SSH service (note: this reduces security; deploying SSH keys instead is recommended).
Reset Fails After Clicking the Panel ButtonThe Instance Is Busy, a Snapshot Is Being Created, or an Unofficial Custom Kernel / Encrypted Filesystem Is in Use.Record the complete error message, use Stop in the panel to shut down the instance, then try the reset again. If it still fails, mount a Rescue image or submit a support ticket for investigation.

Credential Security and Operations Best Practices#

  1. 全面弃用单一弱密码,改用强随机凭据
    Linux systems directly exposed on a public IP are highly susceptible to automated port 22 brute-force attacks. A root password should include uppercase and lowercase letters, digits, and symbols, preferably exceed 16 characters, and be stored centrally in a professional password manager.

  2. Use SSH Key-Pair Authentication in Production
    Generate a modern-standard Ed25519 key or a high-bit-length RSA key, deploy the public key to the server, and completely disable password authentication after verifying that it works:

    bash
    # 在 /etc/ssh/sshd_config 中设置并保存后重启服务
    PasswordAuthentication no
    PermitRootLogin prohibit-password
  3. Protect the Provider's Control Panel (Enable 2FA)
    由于控制面板具备 Passed 底层虚拟化接口直接销毁数据、重装系统或 Reset root 权限的能力,控制面板的凭据泄露风险远高于单一服务器。建议在 BandwagonHost 客户中心与 DMIT 账户中强制启用基于 TOTP(如 Google Authenticator、1Password)的双因素认证(2FA)。

  4. Record Separate Credentials Systematically
    Create standardized asset entries in your password manager. For each server, clearly distinguish and record at least the following fields:

    • Client Portal Account(Official Website Account / Password / 2FA)
    • Panel URL & Credentials( BandwagonHost 专用:KiwiVM Direct 登录地址及面板密码)
    • Server Public IP & Custom SSH Port(Public IP and Provider-Assigned Random SSH Port)
    • System Root Credentials & SSH Key Passphrase(Linux root password and the corresponding private key passphrase)