EXPPWD user updates password
search cancel

EXPPWD user updates password

book

Article ID: 276937

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

Password History shows EXPPWD user updates password

There is no EXPPWD user has been created by PAM Administrator. Who is this user and why does the password update occur?

Environment

PAM 4.x

Resolution

EXPPWD is an internal PAM user that is used by Expired Password Service to update password when it is expired. The password update was triggered by "Automatically Update Expired Passwords" setting in Settings >> Credential Manager >> "General Settings" tab.

There is a background thread for expired passwords that is started whenever tomcat (CSPM)  starts up. The task will only perform the update expired passwords only when it is enabled from the UI ( "Automatically Update Expired Password" is selected in Settings >> Credential Manager >> General Settings page) but the task is always running in the background at 12 hours interval by default.

To avoid this kind of password update, de-select "Automatically Update Expired Passwords" box.