Disable vSphere waiter accounts or change their passwords to suit auditing requirements
search cancel

Disable vSphere waiter accounts or change their passwords to suit auditing requirements

book

Article ID: 434126

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

The "waiter-<UUID>" accounts in vSphere may be flagged by security audit as needing to have their passwords rotated.

Environment

This account is present in all vSphere versions

Cause

These accounts are used for the Auto Deploy service in vSphere. As such, they require a high privilege level to function correctly.

The waiter accounts' passwords do not expire, the recommendation is not to change these passwords as they are referenced in an internal database.

More information: Default Accounts in VMware vSphere

Resolution

If Auto Deploy is not in use, these accounts can be safely disabled or deleted via the vSphere UI.

Once the accounts are deleted, they can be recreated using ESXi bootup through Auto-Deploy stuck at /vmw/rbd/host/######/waiter.tgz and they will have new, randomized passwords.