This guide needs root access. Root is the all-powerful admin user. It is for VPS and dedicated server owners running CentOS or a similar system.
What is a kernel?
The kernel is the core of an operating system. It is the part that talks to the computer's hardware, like a driver for the whole machine. A hardened kernel has extra safety rules added by a security patch. Some old cPanel setups used one, often from the Grsecurity project. Hardened kernels can clash with some software and can stop things from working.
Warning: Changing the kernel can stop the server from starting. Take a full backup or snapshot first. Make sure you can reach a console for recovery.
Steps
- Log in to the server over SSH as root.
- Check which kernel is running:
It prints the kernel version. A hardened one often has "grsec" in the name.uname -r - List the kernels that are installed:
rpm -qa | grep kernel - Install the standard kernel if it is missing:
yum install kernel - Open the boot menu file:
On newer systems the file is different. Usenano /boot/grub/grub.confgrub2-set-defaultinstead. - Find the line that says
default=. Change the number to the position of the standard kernel. The first entry is number 0. - Save the file. Press Ctrl+O then Enter, then Ctrl+X.
- Restart the server:
reboot - After it starts, log in again and run
uname -r. The name should no longer include the hardened tag.
You may also need to check settings that point to the old kernel, for example the cPanel update options. Look under Update Preferences in WHM.
Tip: CentOS 6 and older systems are old. Newer systems follow similar ideas but use different boot files.
Quick recap
- The kernel is the core of the operating system.
- A hardened kernel adds extra security rules but may cause problems.
- Back up first, install the standard kernel and set it as default.
- Reboot and confirm with
uname -r. - Ask support if the server does not come back.