When connecting to the vCenter Server Appliance (vCSA) via SSH (PuTTY) as the root user, you may be prompted to reset your password before being allowed to access the command line. This occurs even if you believe the password should still be valid. This article provides steps to satisfy the password reset requirement using the Management Interface and how to configure the expiration policy.
Product: VMware vCenter Server Appliance
Versions: 6.x, 7.x, 8.x
The root user password has expired according to the security policy defined within the vCenter Server Management Interface (VAMI).
If you cannot log in via SSH due to the reset prompt, follow these steps:
Open a web browser and navigate to the vCenter Server Management Interface (VAMI) at https://vcenter_fqdn:5480.
Log in using an SSO administrator account (e.g., administrator@vsphere.local).
Click the Actions menu in the top-right corner.
Select Change Root Password.
Enter the Current Password and the New Password, then confirm the change.
To prevent or manage future password resets:
Log in to the VAMI (https://vcenter_fqdn:5480) specifically as the root user.
Navigate to the Administration tab in the left sidebar.
In the Password expiration settings section, click Edit.
Choose your preferred policy:
No: The root password will never expire.
Yes: Enter the number of days the password remains valid and an email address for expiration warnings.
Click Save.