Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to switch from a hardened kernel to a standard kernel

Some servers run a special locked-down kernel. This guide shows how to go back to the standard one.

WHM2 min read9 steps

This guide needs root access. Root is the all-powerful admin user. It is for VPS and dedicated server owners running CentOS or a similar system.

What is a kernel?

The kernel is the core of an operating system. It is the part that talks to the computer's hardware, like a driver for the whole machine. A hardened kernel has extra safety rules added by a security patch. Some old cPanel setups used one, often from the Grsecurity project. Hardened kernels can clash with some software and can stop things from working.

Warning: Changing the kernel can stop the server from starting. Take a full backup or snapshot first. Make sure you can reach a console for recovery.

Steps

  1. Log in to the server over SSH as root.
  2. Check which kernel is running:
    uname -r
    It prints the kernel version. A hardened one often has "grsec" in the name.
  3. List the kernels that are installed:
    rpm -qa | grep kernel
  4. Install the standard kernel if it is missing:
    yum install kernel
  5. Open the boot menu file:
    nano /boot/grub/grub.conf
    On newer systems the file is different. Use grub2-set-default instead.
  6. Find the line that says default=. Change the number to the position of the standard kernel. The first entry is number 0.
  7. Save the file. Press Ctrl+O then Enter, then Ctrl+X.
  8. Restart the server:
    reboot
  9. After it starts, log in again and run uname -r. The name should no longer include the hardened tag.

You may also need to check settings that point to the old kernel, for example the cPanel update options. Look under Update Preferences in WHM.

Tip: CentOS 6 and older systems are old. Newer systems follow similar ideas but use different boot files.

Quick recap

  • The kernel is the core of the operating system.
  • A hardened kernel adds extra security rules but may cause problems.
  • Back up first, install the standard kernel and set it as default.
  • Reboot and confirm with uname -r.
  • Ask support if the server does not come back.