Consoleuser or support password lost or forgotten - VCF Operations for Networks
search cancel

Consoleuser or support password lost or forgotten - VCF Operations for Networks

book

Article ID: 310723

calendar_today

Updated On:

Products

VCF Operations for Networks

Issue/Introduction

  • Unable to authenticate to Platform node or Collector node in 9.0.2 using consoleuser or support accounts via local CLI login or SSH login. Error is "Access denied".
  • Has been observed during a VCF 9.1 upgrade 
  • May occur with simple deployment or clustered deployment
  • Authentication to the consoleuser account to enable CLI commands of VCF Operations for Networks Platform or Collector nodes fails
  • This occurs when the consoleuser account password is lost, forgotten, or unknown
  • This issue is frequently reported in versions 6.x through 9.0.2 during administrative maintenance or upgrade cycles

NOTE:  VCF Operations for Networks was formerly named Aria Operations for Networks (AON), and prior to that was named vRealize Network Insight (vRNI).

Environment

VCF Operations for Networks 6.x - 9.0.2

 

Cause

  • The consoleuser password, which is required for high-level CLI management and for resetting the password for the support account, has been misplaced or changed to a unknown value, differing from what is expected.
  • Without consoleuser access, administrative password modification via the modify-password utility is not possible

Resolution

Recovery of the consoleuser account requires Broadcom Support intervention to gain root access, followed by customer steps.

  1. Broadcom Support steps:
  2. Launch the appliance Web Console through vCenter or the ESXi host.
  3. Log in using the root account (Broadcom Support restricted).
  4. Execute the command to reset the consoleuser password.  Share the password with the customer. Command format:

    passwd consoleuser ##########
  5. Log out of the root session.
  6. Customer steps:
  7. Log in as consoleuser using the password assigned in Step 4.
  8. Reset the consoleuser account password by running the built-in utility: modify-password.  Command format:
      
    modify-password system --user consoleuser


  9. Reset the support account password by running the built-in utility: modify-password.  Command format:  

    modify-password system --user support
  10. Log out as consoleuser
  11. Log in as consoleuser using the password modified in step 8, to confirm that SSH access is restored for the consoleuser account.
  12. Log out as consoleuser (again)
  13. Log in using the support account with the password set in Step 9, to confirm that SSH access is restored for the support account.

Note: To speak with a customer representative or a Support Engineer see KB 206567 - Contact Broadcom support and see the section entitled "Create a Support Case".

Additional Information

If the consoleuser password is known and only the support or admin password needs to be changed, refer to KB 324470 - How to update/change and reset password for GUI/SSH and CLI usernames in VCF Operations for Networks.