Web

How Do You Install cPanel and WHM? A Step by Step Guide

Talha Aslan 19 min read 1 views

How do you install cPanel, and how does it relate to WHM?

To install cPanel, you run the official installer script as root on a fresh, supported Linux server with a static IP, a fully qualified hostname and a valid license. WHM is the server administration layer; cPanel is the per account control panel. Both arrive together in one installation.

That split matters more than it first appears. In WHM you set the hostname, nameservers, firewall and backup plan for the whole machine. Meanwhile, inside cPanel each site owner handles email, databases and files for one account. In short, WHM runs the server and cPanel runs the account.

This guide walks through how to install cPanel using the official cPanel documentation: prerequisites, licensing, downloading and inspecting the installer, the first WHM login and a post install checklist. We are a digital marketing and web team, not a hosting company. Therefore we only quote commands and setting names the way the official docs show them. If you have not picked a panel yet, our Plesk vs cPanel comparison is a better first stop.

Who should install cPanel, and when should you leave it to your host?

Anyone with root access to a VPS or dedicated server, plus some comfort on the SSH command line, can run the installer. That said, finishing the install is only the start. Updates, firewall rules, backups and license renewals need ongoing attention.

We recommend leaving the job to your hosting provider in these cases:

  • Your provider already sells a VPS plan with cPanel installed and licensed.
  • The server will run something that cannot go down, such as an online store, and nobody on your team knows Linux.
  • You do not have root access. The official docs also tell you to contact your system administrator or host in that case.
  • The server already hosts sites, another control panel or hand installed services.

For most small businesses a managed VPS with cPanel preinstalled is the saner choice. In practice the provider has already validated the OS template, the network setup and the license binding. If you are still deciding between server types, our VPS vs cloud server vs VDS guide helps. Otherwise, follow the steps below in order.

Which operating systems does cPanel support?

The official cPanel system requirements page lists AlmaLinux OS, CloudLinux, Rocky Linux and Ubuntu. Each distribution has its own page with version details, and those details change over time. So check the current list before you start.

When we read the docs, the AlmaLinux page listed versions 8, 9 and 10, while the Ubuntu page listed only 24.04 LTS. The Ubuntu page also explains that cPanel supports LTS releases only. When a new Ubuntu version gains support, the previous one is eventually deprecated.

Two more warnings deserve attention. First, cPanel says it only tests against official AlmaLinux upstream releases, so prebuilt images and templates may cause install issues. Second, ARM architecture is not supported. As a result, if you picked a cheap ARM cloud instance, the install will stop at step one.

If you still have an old CentOS box, do not try to reuse it for cPanel. Starting clean on a supported distribution causes fewer license and security headaches later.

What hardware do you need to install cPanel?

The docs give separate minimum and recommended values. However, the same docs warn that a server meeting only the minimum may not work well under heavy load. The table below puts the AlmaLinux and Ubuntu requirement pages side by side.

RequirementAlmaLinux (8, 9, 10)Ubuntu 24.04 LTS
Processor1.1 GHzMinimum 1.1 GHz, recommended 2 GHz
RAMMinimum 2 GB, recommended 4 GBMinimum 2 GB, recommended 4 GB
DiskMinimum 20 GB, recommended 40 GBMinimum 20 GB, recommended 40 GB
Architecture64 bit, no ARM64 bit, no ARM
OS firewall to stop before installfirewalldufw
Tool the installer uses for Perlyumapt

Three details sit outside the table. If you plan to run the ClamAV scanner, the docs recommend at least 3 GB of RAM. In addition, installs and upgrades need at least 5 GB of extra space in /usr/local/cpanel. Finally, on a single partition the base install needs at least 1,000,000 inodes, plus at least 50,000 inodes per cPanel account. The installer checks memory up front and exits with an error if the server falls short.

What are the hostname and IP address requirements?

Networking is the part people skip most often. According to the official requirement pages, your hostname must:

  • Be a registered, fully qualified domain name, for example server.example.com.
  • Not match any domain you plan to host on the server.
  • Stay within 60 characters.
  • Resolve to a valid IPv4 or IPv6 address.

If the hostname does not resolve, cPanel will assign one automatically. Still, creating an A record under your own domain and using that as the hostname keeps things tidy. You can confirm the record with our DNS lookup tool.

The IP rules are even stricter. The server needs a static IP address; an address handed out by DHCP will not work. You also need at least one IPv4 address, because an IPv6 only cPanel server is not possible. Behind NAT, you need a 1:1 NAT and NAT loopback setup. The install page adds that cPanel only licenses publicly visible, static IP addresses with working DNS resolution. If the server will send mail, plan reverse DNS as well; our PTR record guide covers why.

How do you get a cPanel license, and is there a free trial?

Yes. For a new installation, the docs describe a free 15 day trial license. To activate it, you need a cPanel Store account with a verified email address. Before the trial ends, you must move to a paid license.

Licenses bind to an IP address, and every server needs its own. The docs state plainly that trying to use one license across several servers may get it locked. You have two ways to buy one:

  1. Directly from the cPanel Store, for your server's IP address.
  2. Through a cPanel partner or your hosting provider, many of whom bundle the license into the VPS invoice.

Either way, know the server's permanent IP before you buy. If the IP changes later, you need to update the license too. Also note one quirk: if an active CloudLinux license exists on that IP, the installer converts an AlmaLinux system to CloudLinux automatically. You can block that with an option we cover below. If you do want CloudLinux, our CloudLinux license guide explains the process.

We do not quote prices here because they change often. Check the cPanel Store or your provider for current terms.

Why does cPanel need a fresh operating system?

The official install page is blunt: only install cPanel and WHM on a freshly installed operating system. The installer sets up every service it needs on its own. If you install Apache, Nginx, MySQL or another panel first, you will hit compatibility problems. Worse, if you install services that depend on cPanel while the installer runs, the install fails outright.

In practice that means one thing. Provision the server from your provider's dashboard with a minimal image of a supported distribution, then add nothing on top. For example, if you once tried aaPanel on a VPS, reinstall the OS instead of trying to clean it up.

Removal is the other big point. According to the docs, cPanel ships no uninstaller; to remove it, you have to reformat the server. So treat the install as a one way door, not a casual experiment. If you are unsure, test on a separate, empty server first. Then move to the real one.

How do you prepare the server before installing?

Before you install cPanel, preparation takes four steps, all as root. First, update the OS and set the hostname:

dnf -y update
hostnamectl set-hostname server.example.com
hostname -f

On Ubuntu, use apt update and apt upgrade instead. The last command should print the fully qualified hostname.

Second, deal with SELinux. The AlmaLinux requirements page says SELinux must be disabled. Check its state with the sestatus command. To turn it off, set SELINUX=disabled in /etc/selinux/config and reboot. Make sure no # sits in front of that line, otherwise the system ignores it.

Third, stop the OS firewall. The docs recommend disabling it before the install, then setting up CSF or APF afterwards. These are the official AlmaLinux commands:

iptables-save > ~/firewall.rules
systemctl stop firewalld.service
systemctl disable firewalld.service

On Ubuntu, swap firewalld.service for ufw.service. The first line saves your existing rules. Fourth, protect your SSH session. Because the install can take a while, a dropped connection can interrupt it. So we suggest a session manager such as tmux. If you want to tighten SSH at this stage too, our swap file and SSH hardening guide walks through it.

How do you download and inspect the installer before you install cPanel?

The official docs give a single command that downloads and runs the installer in one go. We deliberately split that flow into steps, because looking at a file before you run it as root is a good habit. After you open a tmux session, download the file:

tmux new -s cpanel
cd /home
curl -o latest -L https://securedownloads.cpanel.net/latest

These commands switch to /home and save the installer as a file named latest. The address comes from the official install page. Do not use a copy from another site or a shortened link. Next, inspect the file without running it:

ls -lh latest
head -n 40 latest

The first command shows the file size. If it is tiny, say a few hundred bytes, the download most likely grabbed an error page. The second command prints the top of the file. You should see a shell script header there, not HTML. That way you lower the risk of running the wrong file with root rights.

This check is not a security audit. However, it catches common problems such as a truncated download, a wrong URL or an interfering proxy before anything touches your system.

How do you run the installer, and how long does it take?

Once you have inspected the file, start the install with one command:

sh latest

The script checks the system first. Then it downloads the required packages and sets up services. If Perl is missing, it tries to install it with yum on AlmaLinux or apt on Ubuntu. A lot of output scrolls past; that is normal. To review the install log later, look at /var/log/cpanel-install.log.

We will not give you a fixed duration, because the docs do not give one either. Time depends on CPU, disk speed and the server's network connection. According to the docs, new installs use a fast installation mode by default, and that mode cuts install time drastically.

If your SSH connection drops mid install, do not panic. Reconnect and run tmux attach -t cpanel to return to the same session. If you skipped tmux and the connection dropped, the script may have stopped halfway. In that case, we recommend reinstalling the OS from your provider's panel and starting clean rather than patching things up. When the install finishes, the screen shows how to reach WHM.

Which installer options are worth knowing?

When you install cPanel with default settings, the result suits most setups. Still, the official customize your installation page lists options you can append to the command. These are the most useful in practice:

  • --skip-cloudlinux: skips the automatic CloudLinux conversion even when a license exists.
  • --skip-wptoolkit: skips the automatic WP Toolkit install.
  • --skip-imunifyav: skips the automatic ImunifyAV install.
  • --confirm: asks for confirmation before the script runs.

For example, to stay on AlmaLinux, you would run sh latest --skip-cloudlinux. The docs also list a --force option that pushes the install through on a configuration cPanel does not recommend. Unless you know exactly why you need it, leave it alone.

In addition, you can predefine basics such as the IP address, nameservers and contact email in /etc/wwwacct.conf before the install. For a single server this is overkill, because you enter the same details at the first WHM login anyway. For teams that build many servers from one template, it saves time.

What happens at your first WHM login?

After the install, open the server's IP address or hostname on port 2087 in your browser, for example https://192.0.2.10:2087. The username is root and the password is the server's root password. The official Getting Started in WHM page describes the first login flow:

  1. Security warning: your browser may complain if the server still uses a self signed certificate.
  2. Legal agreements: you cannot continue until you accept the license agreement and related terms.
  3. Trial license: next comes the screen to start the free trial.
  4. Contact and nameservers: you enter a contact email and two nameservers.

Do not rush the nameserver step. According to the docs, without nameservers you will not be able to create new accounts. For instance, you would enter ns1.example.com and ns2.example.com, and those names also need to exist at your domain registrar.

The contact email matters too, since server alerts go there. You can change both later in WHM's Basic WebHost Manager Setup screen. So if you hurried through the first login, you still have a chance to fix it.

How do you verify that the cPanel license is active?

If WHM shows no license error after the first login, the license is usually fine. Even so, confirming it explicitly before you call the job done is a good habit. The official license troubleshooting doc offers two routes.

The first route is on the web. You enter the server's public IP on cPanel's License Verification page and see the license status. That page lists cPanel and other products such as CloudLinux on separate rows. In other words, CloudLinux can show as active while the cPanel license has expired, so read both rows.

The second route is the command line. As root, run this script:

/usr/local/cpanel/cpkeyclt

If the license works, the script returns no message. If it takes more than a few seconds, the server may be struggling to reach the license servers. In that case, the docs tell you to check connectivity, hostname resolution and the server's date and time settings. Time settings are easy to miss, and a wrong clock can trigger license errors. If the problem persists after that, opening a ticket with cPanel customer service is the right next step.

How do you set up a firewall after you install cPanel?

During preparation you stopped the OS firewall. Therefore the server may be exposed right now, and your first job after the install should be setting up a firewall. The official requirement pages suggest third party tools such as CSF or APF for this.

CSF is a firewall widely used on cPanel servers, and it adds a management screen inside WHM. We do not repeat the install steps, port lists or testing mode here; those live in our CSF firewall installation guide. The key point is to keep the ports for cPanel and WHM services open. WHM uses port 2087, cPanel uses 2083 and Webmail uses 2096. If those close, you lock yourself out of your own panel.

On top of the firewall, we suggest turning on two features in WHM's Security Center: cPHulk for brute force protection and two factor authentication for the root account. Also, switching SSH from passwords to keys shrinks the attack surface noticeably. Even so, none of these replaces regular updates.

How do you turn on backups?

This is the step most people miss. The official Backup Configuration doc states that scheduled backups are disabled by default. So a fresh cPanel server does not back anything up on its own.

You enable backups in WHM's Backup Configuration screen. After you tick Enable Backups, you pick one of three backup types:

  • Compressed: uses less disk space but takes longer.
  • Uncompressed: runs faster but takes more disk space.
  • Incremental: combines hard links and files, so unchanged files do not get copied again.

Next, set the schedule and retention. The setting that really matters, though, is the Additional Destinations tab. Backups that live only on the same server's disk do nothing for you if that disk fails or the server disappears. So define at least one remote destination, and after the first run, restore a test account to prove it works.

We cover how many copies to keep, how often and where in our website backup strategy guide. If you also want separate database dumps, our mysqldump and pg_dump guide helps.

Where do you manage PHP versions and web server settings?

On cPanel servers, Apache, PHP and related modules run through EasyApache 4. The EasyApache 4 screen under Software in WHM lets you choose which PHP versions and extensions to install. The official update doc also recommends updating Apache's PHP from that screen.

Right after the install, decide which PHP versions your sites actually need. For example, an older WordPress plugin may break on a newer version. On the other hand, you should not keep an end of life PHP version around for long, since it no longer receives security fixes.

You pick the default PHP version, and the version per account, in MultiPHP Manager. Each site can run on a different version. We explain the steps, the difference from PHP Selector and common errors in our cPanel PHP version guide.

Keep in mind that PHP extensions you install by hand do not update automatically. The docs say you have to update those yourself. So stick to the packages inside EasyApache 4 where you can; that way the panel carries the update burden for you.

How should you configure automatic updates?

The official update doc strongly recommends updating cPanel and WHM regularly on every server. WHM shows the current version near the top right of the interface. On the command line, this command gives you the same information:

/usr/local/cpanel/cpanel -V

You manage update behavior in WHM's Update Preferences screen. There you choose which release tier the server follows and whether updates arrive automatically or manually. For a production server, we suggest a stable tier with automatic updates on. Testing new features before everyone else is an unnecessary risk on a machine that hosts live sites.

To update by hand, use WHM's Upgrade to Latest Version screen, or run this script as root:

/usr/local/cpanel/scripts/upcp

This script updates cPanel along with most system packages. After a kernel update, however, you need to reboot, otherwise the new kernel does not load. The docs also warn that third party repositories can cause problems with updates. Therefore avoid adding random repositories to the server.

What belongs on your post install checklist?

After you install cPanel, and before you migrate the first site, tick off the list below one item at a time. It condenses the warnings in the official docs and the steps above:

  1. You can log in to WHM on port 2087 and you accepted the legal agreements.
  2. The license shows as active on the License Verification page and cpkeyclt returns no error.
  3. The hostname is fully qualified, does not clash with your sites and resolves to the right IP.
  4. Two nameservers exist in WHM and at your registrar.
  5. The hostname has a valid SSL certificate, confirmed with our SSL checker.
  6. CSF or a similar firewall is active and the panel ports are open.
  7. cPHulk and two factor authentication for root are on.
  8. Scheduled backups are on, at least one remote destination exists and you tested a restore.
  9. The PHP versions you need exist and a default version is set.
  10. Updates are automatic and on a stable tier.

Once the list is done, create a test account and publish a simple page. Then send and receive an email to check the mail side. That way you catch problems on your own test account before real customer accounts move over. For a refresher on what certificates actually do, see our SSL certificate explainer.

Which errors show up most often during setup?

The official troubleshooting doc covers the most frequent cases one by one. Here is a summary:

SymptomLikely causeWhat to do first
Certificate warning in the browserHostname does not resolve, so only a self signed certificate existsMake the hostname an FQDN and update it in Change Hostname
License File Expired or similarExpired license, IP mismatch or wrong clockCheck the License Verification page and the cpkeyclt output
Perl must be installed errorThe package manager is brokenRetry the Perl install with yum or apt
Cannot create new accountsNo nameservers definedAdd nameservers in Basic WebHost Manager Setup

The certificate warning follows a simple logic. The installer first adds a self signed hostname certificate. Then, if your provider allows it, it tries to get a free hostname certificate. If the hostname does not resolve, that step fails and the browser keeps warning you.

For anything else, start with the install log. If the install broke halfway and the server holds no live data yet, reinstalling the OS and starting clean is often faster than repairs.

Your own cPanel server or a managed VPS?

Before deciding, it helps to compare both approaches side by side:

TopicYour own cPanel installManaged VPS with cPanel
OS and network prepYour responsibilityDone by the provider
License bindingYou tie it to the IPIncluded in the plan
Security and updatesEntirely yoursDepends on the plan, read the contract
FlexibilityHighMay be limited by the provider's template

Running your own install gives you full control. On the other hand, you also own every problem. If you plan to sell hosting to several clients, our cPanel reseller hosting guide describes a lighter way to start. If you want to automate billing and account creation, our WHMCS overview covers the next step.

So what is the right way to plan it?

In short, the decision to install cPanel involves more than one command. A supported, fresh OS, a static IP, a fully qualified hostname and a valid license are prerequisites. Download and inspect the installer before you run it, enter nameservers correctly at the first WHM login, and switch on the firewall and backups right after the install. Those steps carry most of the risk.

We do not operate servers. However, we regularly help clients weigh infrastructure choices on website, online store and custom software projects. If you cannot decide where your site should run, or you are planning a new project, our web design service and custom software development team can help at that stage. As for day to day server management, we always recommend leaving it to a hosting provider or an experienced system administrator.

Frequently Asked Questions

Is cPanel free to install?
No, cPanel runs on a paid license. However, a new installation can activate a free 15 day trial license. To do that, you need a cPanel Store account with a verified email address. If you do not switch to a paid license before the trial ends, the panel stops working, so check current pricing with cPanel or your host.
Which operating systems can I install cPanel on?
The official docs support AlmaLinux OS, CloudLinux, Rocky Linux and Ubuntu. Supported versions change over time. When we checked, Ubuntu support covered only 24.04 LTS, while AlmaLinux covered versions 8, 9 and 10. Check the current system requirements page before you start, and avoid ARM based servers entirely.
How long does a cPanel installation take?
The official docs do not give a fixed time, because it depends on CPU, disk speed and network connection. New installs use a fast installation mode by default, which shortens the process considerably. Since a dropped SSH connection can interrupt the script, we recommend starting the install inside a tmux session.
Can I uninstall cPanel later?
No. According to the official docs, cPanel does not provide an uninstaller. If you want to remove it, you have to reformat the server. That is why you should not treat the install as a quick experiment. If you are unsure, try it on an empty test server first, then move to the production machine.
How do I log in to WHM after the install?
Open the server's IP address or hostname on port 2087 in your browser, for example https://192.0.2.10:2087. Log in as root with the root password. On the first login you accept the legal agreements, start the trial license, then enter a contact email and two nameservers.
Should I install cPanel myself if my host offers it preinstalled?
Usually not. A managed VPS with cPanel preinstalled comes with the OS, network and license binding already validated. Your own install gives you full control, but you also take on all security, backup and update work. If nobody on your team knows Linux, the managed plan is the safer start.
  • cPanel
  • WHM
  • install cPanel
  • VPS
  • AlmaLinux
  • server management
  • web hosting
Share:
Talha Aslan

Google Partner digital marketing expert. Hands-on with SEO, Google Ads, web design and e-commerce projects since 2012; every post here comes from that experience.

Next project

Let's talk about your project.

Your brief goes straight to Talha Aslan and team: strategy led by Talha, delivery by an experienced team. The first consultation is free; we listen and come back with a clear roadmap.