Update root password and expiration settings in vCenter Server Appliance
search cancel

Update root password and expiration settings in vCenter Server Appliance

book

Article ID: 426611

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

When connecting to the vCenter Server Appliance (vCSA) via SSH (PuTTY) as the root user, you may be prompted to reset your password before being allowed to access the command line. This occurs even if you believe the password should still be valid. This article provides steps to satisfy the password reset requirement using the Management Interface and how to configure the expiration policy.

Environment

 

Product: VMware vCenter Server Appliance

Versions: 6.x, 7.x, 8.x

 

Cause

The root user password has expired according to the security policy defined within the vCenter Server Management Interface (VAMI).

Resolution

Part 1: Resetting the root password via VAMI

If you cannot log in via SSH due to the reset prompt, follow these steps:

  1. Open a web browser and navigate to the vCenter Server Management Interface (VAMI) at https://vcenter_fqdn:5480.

  2. Log in using an SSO administrator account (e.g., administrator@vsphere.local).

  3. Click the Actions menu in the top-right corner.

  4. Select Change Root Password.

  5. Enter the Current Password and the New Password, then confirm the change.


Part 2: Configuring Password Expiration Settings

To prevent or manage future password resets:

  1. Log in to the VAMI (https://vcenter_fqdn:5480) specifically as the root user.

  2. Navigate to the Administration tab in the left sidebar.

  3. In the Password expiration settings section, click Edit.

  4. Choose your preferred policy:

    • No: The root password will never expire.

    • Yes: Enter the number of days the password remains valid and an email address for expiration warnings.

  5. Click Save.