Also, something to consider, if you (or an attacker) have physical or remote access, game is over anyways....irregardless of passwords.Interesting point: this server is a Xen-domU and although I have access to the physical server, it is a bit more complicated to do interrupt the boot process to get root access.
If the root-filesystem of the domU is not encrypted you can just halt the server and mount the filesystem in the dom0. Ciao, Alberto.