AlmaLinux 10 has been a supported cPanel & WHM platform since version 132, and with Rocky Linux dropped in 134 it is now the natural choice for a new RHEL-family cPanel server. The installer is straightforward, but most failed installs come from skipping the preparation stage: a hostname that is not a fully qualified domain name, NetworkManager left running, or a partially configured minimal image. This checklist takes you from a bare AlmaLinux 10 install to a licensed WHM with sane defaults.
Table of Contents
Short answer: On a clean minimal AlmaLinux 10 server, set a fully qualified hostname that is not a hosted domain, disable NetworkManager and SELinux, run dnf -y update and reboot, then as root run cd /home && curl -o latest -L https://securedownloads.cpanel.net/latest && sh latest inside a screen session. Log in at port 2087, complete the setup wizard, enable two-factor authentication and Host Access Control, leave automatic updates on, and install the cPanel CSF fork before creating any accounts.
Before you start
Check the basics before running anything. You need a clean minimal AlmaLinux 10 installation with at least 2 GB of RAM (4 GB or more for anything that will host real sites), a 40 GB or larger disk, a static public IPv4 address, and outbound access on ports 80, 443 and 2089 for licensing. The server must not have any other control panel, web server or mail server installed.
The hostname must be a fully qualified domain name that is not the same as any domain you will host, for example srv01.example-hosting.net, and it should have a working A record before you start so that AutoSSL can issue the hostname certificate later. Set it now:
hostnamectl set-hostname srv01.example-hosting.net
NetworkManager must still be disabled before a RHEL-family install; the installer refuses to continue while it is active. On AlmaLinux 10 the replacement is a static configuration through the legacy network scripts or a pre-written ifcfg file, so make sure your network settings are already working outside NetworkManager before you disable it:
systemctl disable --now NetworkManager
systemctl enable network 2>/dev/null || true
If a cloud image depends on NetworkManager for DHCP, configure the interface statically first. Confirm name resolution and outbound access afterwards:
ping -c 3 almalinux.org
Finally, bring the OS fully up to date and reboot so the installer runs on the current kernel:
dnf -y update && reboot
Disable SELinux and check firewalls
cPanel does not support running with SELinux in enforcing mode. Set it to disabled in /etc/selinux/config and reboot, or at minimum set it to permissive for the install. Check the state with getenforce. The default firewalld service can stay installed, but you will most likely replace it with the cPanel CSF fork or Imunify360 after the install, so leave the firewall permissive until WHM is reachable and you can test connectivity to ports 2087 and 2083.
Run the installer
The installer must be run as root from a screen or tmux session, because it takes anywhere from twenty minutes to over an hour depending on disk speed and mirror latency. Download it to /home and run it:
cd /home
curl -o latest -L https://securedownloads.cpanel.net/latest
sh latest
The script pulls the correct build for the tier set in /etc/cpupdate.conf. On a brand-new install the default tier is RELEASE, which is 138 as of late September 2026. If you want the long-term-support branch instead, create /etc/cpupdate.conf before running the installer with CPANEL=lts in it and the installer will fetch 134. See Choosing a cPanel update tier in 2026 for the trade-offs.
The installer sets up EasyApache 4 with a default profile, MariaDB 10.11, Exim, Dovecot, Pure-FTPd, BIND and the cPanel services. Do not interrupt it; a fresh reinstall is easier than repairing a partial one.
First login and licence
When the installer finishes, log in at https://srv01.example-hosting.net:2087 as root. Your licence is tied to the server’s main IP, so if the WHM login shows a licence error, check that the IP is registered in your licence provider’s system and that outbound port 2089 is not blocked. You can trigger a licence refresh manually:
/usr/local/cpanel/cpkeyclt
Work through the initial setup wizard: agree to the licence, set the contact email and nameservers, and confirm the main shared IP. Then make a handful of changes immediately in WHM before any accounts exist.
- WHM → Server Configuration → Tweak Settings: set the maximum hourly emails per domain to a sensible cap and confirm that “Prevent nobody from sending mail” is enabled.
- WHM → Security Center → Two-Factor Authentication: enable it for root before anything else.
- WHM → Security Center → Host Access Control: restrict SSH and WHM to your management IPs.
- WHM → Server Configuration → Update Preferences: leave automatic updates on. The 2026 pattern of root-escalation security releases every few weeks makes this non-negotiable.
- WHM → SSL/TLS → Manage AutoSSL: enable the default provider so the hostname and service certificates are issued.
Install a firewall now. The cPanel-maintained CSF fork installs with /scripts/autorepair cpanel_csf_install, or you can deploy Imunify360 if you have a licence. Once CSF is in place, set TESTING = "0" in /etc/csf/csf.conf and restart it with csf -ra.
Verify
Confirm the build and tier, then check that the core services are healthy:
whmapi1 version
/scripts/restartsrv_cpsrvd --status
systemctl status httpd mariadb exim dovecot named
whmapi1 version should report a current build for your chosen tier, for example 138.0.10 on RELEASE. Create a test account with whmapi1 createacct, browse to its domain, check that uapi --user=testuser SSL installed_hosts shows an AutoSSL certificate after the next run, and send a test email out and in.
Common pitfall
The most frequent failure is a hostname that the installer rejects or that later collides with a hosted domain. If you set the hostname to example.com and then create an account for example.com, mail and SSL for that domain will misbehave in ways that are tedious to unpick. Always use a dedicated subdomain for the server itself. The second most common problem is starting the installer while NetworkManager is still enabled; the fix is simply to disable it and rerun the script, but you will save time by checking systemctl is-active NetworkManager before you begin.
Once the server is up, run our server security audit script to catch anything the wizard missed, and follow Hardening SSH on AlmaLinux 9, which applies equally to AlmaLinux 10.
Install cPanel AlmaLinux 10 at a glance

Official documentation: cPanel & WHM documentation, AlmaLinux wiki, Linux man pages.
Related guides: Ubuntu 24.04 or AlmaLinux 9/10 for a new cPanel server in 2026? · What changed in cPanel 136: unified SSL, Ruby removed, Ubuntu 22.04 dropped, MariaDB 11.8 · Incident response after a cPanel root-escalation CVE: rotating keys, hunting .sorry, auditing sessions.
Frequently asked questions
Does cPanel officially support AlmaLinux 10?
Yes. AlmaLinux 10 has been a supported cPanel & WHM platform since version 132, and with Rocky Linux support removed in 134 it is the recommended RHEL-family choice for new servers on both the LTS and RELEASE tiers.
How long does the cPanel installer take on AlmaLinux 10?
Expect twenty minutes to over an hour depending on disk speed and mirror latency, because the installer downloads and configures EasyApache 4, MariaDB, Exim, Dovecot and the panel itself. Run it inside screen or tmux and do not interrupt it.
Why does the cPanel installer fail with NetworkManager or hostname errors?
The installer refuses to run while NetworkManager is active and rejects a hostname that is not a fully qualified domain name. Configure the interface statically, run systemctl disable --now NetworkManager, set a dedicated hostname such as srv01.example-hosting.net with hostnamectl, and rerun the script.