Remediating passwords updated outside of VMware Aria Suite Lifecycle
search cancel

Remediating passwords updated outside of VMware Aria Suite Lifecycle

book

Article ID: 302049

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

This article provides the steps to remediate a password that was updated outside of Aria Suite Lifecycle. It is part of a group of articles about managing passwords using Aria Suite Lifecycle: Password management with Aria Suite Lifecycle (vRealize Suite Lifecycle Manager) Locker.

The passwords managed by Locker may need to be updated outside of Aria Suite Lifecycle for the following reasons:

The issue may be encountered in Aria Suite Lifecycle by hitting the following error when attempting to update a password:

LCMVACONFIG80003
Failed to update the password.

In these situations, follow the steps described in this article to add the new password in Locker and update the Product Environment information using Lifecycle Operations.

Note: On VCF mode Aria Suite Lifecycle, the passwords are managed by the SDDC Manager rotation tool. Therefore:

If you experience problems with the Password Rotation tool or remediating passwords in SDDC Manager, file a Service Request with the VMware Cloud Foundation team.

In the password remediation process, the Locker and Lifecycle Operations applications are involved:

  • Locker: Creates the password in the Aria Suite Lifecycle database and confirms if the password is being used.
  • Lifecycle Operations: Provides the option to sync the inventory. During the inventory sync, the request will fail; each time it fails, select RETRY and select the new password.

The required flow of actions is as follows:

Note: Step 4. The number of failures depends on the number of service accounts to be validated multiplied by the number of nodes. For a cluster, the error occurs each time for a different password.

Note: Some screenshots of this article are from Suite Lifecycle Manager 8.10; therefore, the old branding is present.

Resolution

Prerequisites

Solution

  1. Validate that the password is valid in the respective appliance or UI.
  2. For root and sshuser (vIDM only), check for login attempt failures.
  3. Validate that the password is not expired or about to expire.
  4. If required, reset the number of login attempt failures.
    pam_tally2 --user=root --reset
    pam_tally2 --user=sshuser --reset
  5. Run the following command to keep the SSH session active in the appliance(s) and monitor the login attempt failures. This is helpful in case an error occurs when typing the password in Locker:
    watch -n 1 "pam_tally2 --user=root"
  6. In VMware Aria Suite Lifecycle, navigate to Locker > Passwords > Add.
  7. Add the password with the following considerations:
    1. The Password Alias and Password are mandatory fields. For Datacenter passwords, the User Name is mandatory. Then click ADD.
    2. The Password Description is optional.
  8. In this example, vIDM sshuser and root are added. The passwords are not in use because they have not been applied to a product using the Lifecycle Operations application.
  9. Navigate to Lifecycle Operations > Environment, and click VIEW DETAILS for the product of interest.
  10. Trigger an inventory sync.
  11. Because the password was updated outside of Aria Suite Lifecycle, the request fails. The number of failures depends on the number of nodes and the number of passwords being updated. For example:
    • On a vIDM cluster, if only the root password was updated, the inventory sync fails 3 times.
    • On a vIDM cluster, if the root and sshuser passwords were updated, the inventory sync fails 6 times.
    • On a single-node vIDM, if the sshuser and root passwords were updated, the inventory sync fails 2 times.
  12. Each time it fails, monitor the username and node that fails. It should fail only once per node and username:
  13. Click RETRY.
  14. Select the new Locker Password Alias, and then click SUBMIT.
  15. Repeat steps 10 and 11 as required based on the expected number of failures explained in step 11.
  16. The inventory sync completes.
  17. Results: The new Locker Password Alias is in use, and the Product Environment page shows the new Locker Password Alias.
  18. Check for login failure attempts in the appliances and reset them if required:
    pam_tally2 --user=root
    pam_tally2 --user=root --reset
  19. Delete the old password in Locker by selecting the vertical ellipsis in the last column.

Additional Information

Main article

Child articles

Changing password KBs

ProductUser / PasswordKB Link
Aria Automation
Aria Automation Config
Aria Automation Orchestrator
rootKB 92254
Aria Operationsroot
admin
KB 92255
Aria Operations for Logsroot
admin
KB 92256
Aria Operations for Networksadmin
support
console user
KB 92257
Aria Suite Lifecycle applianceroot
admin@local
KB 92245
Workspace ONE Accessroot
admin
admin (8443)
KB 92258