This article provides the steps to remediate a password that was updated outside of Aria Suite Lifecycle. It is part of a group of articles about managing passwords using Aria Suite Lifecycle: Password management with Aria Suite Lifecycle (vRealize Suite Lifecycle Manager) Locker.
The passwords managed by Locker may need to be updated outside of Aria Suite Lifecycle for the following reasons:
The issue may be encountered in Aria Suite Lifecycle by hitting the following error when attempting to update a password:
LCMVACONFIG80003
Failed to update the password.In these situations, follow the steps described in this article to add the new password in Locker and update the Product Environment information using Lifecycle Operations.
Note: On VCF mode Aria Suite Lifecycle, the passwords are managed by the SDDC Manager rotation tool. Therefore:
If you experience problems with the Password Rotation tool or remediating passwords in SDDC Manager, file a Service Request with the VMware Cloud Foundation team.
In the password remediation process, the Locker and Lifecycle Operations applications are involved:
Locker: Creates the password in the Aria Suite Lifecycle database and confirms if the password is being used.Lifecycle Operations: Provides the option to sync the inventory. During the inventory sync, the request will fail; each time it fails, select RETRY and select the new password.The required flow of actions is as follows:
Note: Step 4. The number of failures depends on the number of service accounts to be validated multiplied by the number of nodes. For a cluster, the error occurs each time for a different password.
Note: Some screenshots of this article are from Suite Lifecycle Manager 8.10; therefore, the old branding is present.
pam_tally2 --user=root --reset
pam_tally2 --user=sshuser --resetroot and sshuser (vIDM only), check for login attempt failures.pam_tally2 --user=root --reset
pam_tally2 --user=sshuser --resetwatch -n 1 "pam_tally2 --user=root"Locker > Passwords > Add. Password Alias and Password are mandatory fields. For Datacenter passwords, the User Name is mandatory. Then click ADD.Password Description is optional.sshuser and root are added. The passwords are not in use because they have not been applied to a product using the Lifecycle Operations application. Lifecycle Operations > Environment, and click VIEW DETAILS for the product of interest. root password was updated, the inventory sync fails 3 times.root and sshuser passwords were updated, the inventory sync fails 6 times.sshuser and root passwords were updated, the inventory sync fails 2 times.RETRY.SUBMIT. pam_tally2 --user=root
pam_tally2 --user=root --reset| Product | User / Password | KB Link |
|---|---|---|
| Aria Automation Aria Automation Config Aria Automation Orchestrator | root | KB 92254 |
| Aria Operations | rootadmin | KB 92255 |
| Aria Operations for Logs | rootadmin | KB 92256 |
| Aria Operations for Networks | adminsupportconsole user | KB 92257 |
| Aria Suite Lifecycle appliance | rootadmin@local | KB 92245 |
| Workspace ONE Access | rootadminadmin (8443) | KB 92258 |