"Password Expiry" Alarm Not Triggered for Edge Nodes with Expired Root Passwords
search cancel

"Password Expiry" Alarm Not Triggered for Edge Nodes with Expired Root Passwords

book

Article ID: 392915

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

"Failure Domain Down" alarm is reported.


 

  • Resolving the alarm doesn't allow to keep it cleared.
  • No traffic impact is seen.
  • Edge Nodes root Password shows as expired when running get user root password-expiration from admin
  • Password Expiry alarm not triggered, despite alarm definitions being enabled.

 

Environment

VMware NSX 4.1.1

Cause

Due to a potential race condition in versions prior to 4.1.2, the customer may not see the expected password expiration alarms—instead, only the Failure Domain Down alarm may be triggered.

The Failure Domain Down alarm may appear if the root password has expired. Without a valid root password, certain information from the NSX Manager cannot be retrieved, which can trigger this alarm.

Resolution

 

Follow Workaround to reset root password provided in "Failure Domain Down" and "Password Expiry" alarms are reported for nodes.

- Starting with version 4.1.2, users are notified of expired passwords through a separate Password Expiry alarm.