Using Two Factor Authentication
Two factor authentication adds a second layer of security to your hosting account and VPS. This guide shows you how to enable 2FA in the Hostworld client area, cPanel, WHM, Virtualizor and SSH using time-based one-time passwords.
Turn on Two Factor Authentication (2FA) where you sign in with Hostworld: your client area (WHMCS), cPanel or WHM, our Virtualizor VPS panel, or at SSH on your VPS. All use time-based one-time passwords (TOTP) from an authenticator app.
Before you start
- Have a TOTP authenticator app installed on your phone or desktop.
- Make sure the time on your device, and on any server you manage, is correct and syncing with NTP.
- Keep an existing login open while changing login settings so you can undo a mistake.
Step 1: Enable 2FA in the panel you are using
In your Hostworld account (WHMCS)
- Sign in at portal.hostworld.uk, then go to Hello, Name! > Security Settings.
- Click "Click here to Enable", choose Time Based Tokens, and scan the QR code with your authenticator app.
- Enter the 6-digit code from your app to confirm.
- Write down the Backup Code shown and store it safely. It is your recovery if you lose your device.
In cPanel or WHM
- If you manage a server: in WHM go to Security Center > Two-Factor Authentication. Enable the policy. You will see a status banner when it is enabled. You can also allow 2FA for Webmail and configure the Issuer in the Settings tab.
- In cPanel: open Security > Two-Factor Authentication, click Set Up, scan the QR code, then enter the 6-digit code. Team Users are supported.
In Virtualizor (your VPS control panel)
- Open your VPS in Virtualizor from the Hostworld client area.
- Open the Two-Factor Authentication page, choose App (TOTP), then scan the QR code or enter the secret into your app.
- Enter the 6-digit code to finish.
Step 2: Add 2FA to SSH on your VPS
This secures SSH with both your SSH key and a TOTP code. Set up working SSH keys first. Keep your current SSH session open and test a second session before logging out.
Ubuntu 24.04
This installs the PAM module that checks TOTP codes.
sudo apt update
sudo apt install -y libpam-google-authenticator
This creates your secret and emergency codes in ~/.google-authenticator.
google-authenticator
This adds SSH settings to require your SSH key and then a TOTP code. It also disables password-only logins.
sudo tee /etc/ssh/sshd_config.d/2fa.conf >/dev/null <<'EOF'
KbdInteractiveAuthentication yes
PasswordAuthentication no
AuthenticationMethods publickey,keyboard-interactive
EOF
This inserts the TOTP check into PAM immediately above Ubuntu's @include common-auth line. The position matters: added at the end of the file instead, the Unix password modules run first and you get an extra password prompt or an unpredictable prompt order.
sudo sed -i '/^@include common-auth/i auth required pam_google_authenticator.so' /etc/pam.d/sshd
This shows the two lines so you can confirm the module comes first.
grep -n -e pam_google_authenticator -e 'common-auth' /etc/pam.d/sshd
This validates your SSH configuration, then reloads SSH without dropping connections.
sudo sshd -t
sudo systemctl reload ssh
AlmaLinux 9
This enables EPEL and installs the PAM module for TOTP codes.
sudo dnf install -y epel-release
sudo dnf install -y google-authenticator-libpam
This creates your secret and emergency codes in ~/.google-authenticator.
google-authenticator
This writes the same SSH settings as a drop-in file, so the main sshd_config stays untouched. Use KbdInteractiveAuthentication, not the deprecated ChallengeResponseAuthentication.
sudo tee /etc/ssh/sshd_config.d/2fa.conf >/dev/null <<'EOF'
KbdInteractiveAuthentication yes
PasswordAuthentication no
AuthenticationMethods publickey,keyboard-interactive
EOF
This creates a custom authselect profile so your PAM change persists. The command copies the base profile into /etc/authselect/custom/hostworld-2fa/ for you, so do not copy files in by hand.
sudo authselect create-profile hostworld-2fa -b sssd
Open /etc/authselect/custom/hostworld-2fa/system-auth and /etc/authselect/custom/hostworld-2fa/password-auth and add this line near the top of the "auth" section in each.
auth required pam_google_authenticator.so
This selects and applies your custom profile, validates SSH, then reloads it.
sudo authselect select custom/hostworld-2fa --force
sudo authselect apply-changes
sudo sshd -t
sudo systemctl reload sshd
If it does not work
- cPanel shows "Failed to set user configuration: The security code is invalid." Fix the server time and try again. If you do not see 2FA in cPanel at all, it has not been enabled in WHM yet. Open a support ticket and we will enable it for your hosting account.
- You are locked out after changing SSH. Keep your original SSH session open. Validate with
sudo sshd -tbefore reloading. If you are locked out, use the VPS VNC console in Virtualizor to revert the change, or open a support ticket. - SSH asks for your account password as well as the code. On Ubuntu, the PAM line is below
@include common-auth. Move it above that line and reload SSH. - Cannot sign in to the Hostworld client area after enabling 2FA. Use the Backup Code you saved during setup. If you have lost it, open a support ticket and we will reset 2FA for your user.
What next
If you want the background on how these routes differ, or you are not sure which one applies to your service, see our VPS guides. If a step here does not match what you are seeing, open a support ticket and we will check the account with you.
Common questions
What is two factor authentication?
Two factor authentication (2FA) requires you to sign in with two things: your password and a time-based one-time password (TOTP) from an authenticator app on your phone or desktop. This makes your account much harder to access even if someone knows your password.
Can I use two factor authentication on SSH?
Yes. You can require both your SSH key and a TOTP code to sign in via SSH. This guide covers setup for Ubuntu 24.04 and AlmaLinux 9.
What should I do if I lose my authenticator device?
When you enable 2FA, you receive a backup code. Store it safely. Use it to sign in if you lose your device. If you have lost the backup code too, contact support and we will reset 2FA for your user.
Do I need to set the time on my server?
Yes. TOTP codes depend on accurate time. Make sure the time on your device and on any server you manage is correct and syncing with NTP before you enable 2FA.
Can I use 2FA with Team Users in cPanel?
Yes. 2FA is supported for Team Users in cPanel.
Was this article helpful?
0 people found this helpful