When managing a VMware Cloud Foundation (VCF) 9.x environment, customers may experience the following:
VCF 9.x
VCF 9.x is designed with a secure-by-default architectural posture. This framework enforces periodic password rotation for all managed core components to align with modern security standards.
To prevent account "tombstoning" and ensure operational continuity, VMware recommends utilizing the Automatic Rotation feature rather than attempting to disable expiration.
Automating rotations ensures that credentials are refreshed before they can expire or become "tombstoned."
Certain Fleet Management components may currently sit outside the scope of the automated rotation engine.
If a "Never Expire" state is strictly required for specific local accounts (e.g., Audit or Admin) and cannot be managed via SDDC Manager:
chage or passwd command syntax applicable to the photon-based appliances.