Resetting/Unlocking admin & root account passwords on vSphere Replication & Site Recovery Manager
search cancel

Resetting/Unlocking admin & root account passwords on vSphere Replication & Site Recovery Manager

book

Article ID: 312789

calendar_today

Updated On:

Products

VMware Live Recovery VMware vSphere ESXi

Issue/Introduction

  • GNU GRUB menu contains slight changes due to a change of operating system from SUSE Linux to Photon OS.

  • Administrative access to the VMware Live Recovery (VLR) or vSphere Replication appliance management interface (VAMI) is lost.

  • The following error message appears when attempting to log in to the VAMI: "Cannot complete login due to an incorrect token, user name, or password"

  • Root password for the appliance is unknown or locked.

Environment

  • vSphere Replication 8.x

  • vSphere Replication 9.0, 9.0.0.1, 9.0.1, 9.0.2, 9.0.2.1, 9.0.2.2, 9.0.2.3

  • VMware Live Site Recovery 9.0, 9.0.1, 9.0.2, 9.0.2.1, 9.0.2.2, 9.0.2.3, 9.0.2.4

  • VMware Live Recovery 9.0.4, 9.0.5, 9.0.5.1

  • VCF Protection and Recovery 9.1, 9.1.0.0100, 9.1.0.0200

Cause

Root password for vSphere Replication (VR) appliance is not known by the administrator.
vSphere Replication/VLR root password is lost or is locked.

Resolution

  1. Shutdown vSphere replication appliance from vSphere client.
  2. Delay the boot sequence of the VM.
  3. Power on vSphere replication appliance. When the Photon OS splash screen appears, press 'e' to enter GNU GRUB edit menu.

     Note:The Photon OS splash screen only appears very briefly, so be quick about it. It is better to use VMware Remote Console rather than the Web Console.

    1. In the GNU GRUB edit menu, go to the end of the line that starts with linux, add a space and type rw init=/bin/bash. After adding these values, GNU GRUB edit menu should look exactly like this:


       For 8.4 the screen will look different.

      VLSR9.X

      init=/bin/bash

    2.  Press the F10 key to boot and at the bash command prompt mount the root partition 

                 mount -o remount, rw /
      Enter passwd then enter to change the password

      passwd
               New password: <enter new password>
      Retype new password: <repeat password>
      passwd: password updated successfully ​​​

      Note : The above will change only root password, if you need to change admin password need to perform additional steps as below

      passwd admin
      New password: <enter new password>
      Retype new password: <repeat password>

           passwd: password updated successfully 



      1. If admin account password is locked, VAMI page for appliance will fail to login,

      2. For product version 8.8 and above you will check and clear the lock with the following command

        pam_tally2 -u root ----->If locked run: 
        /sbin/pam_tally2 -r -u root
        
        pam_tally2 -u admin ----->If locked run:
        /sbin/pam_tally2 -r -u admin
      3. For product  version 8.8 and VLSR 9.x use the command 

        faillock --user root  ----->If locked run:
        /sbin/faillock --user root --reset 
        
        faillock --user admin  ----->If locked run:
        /sbin/faillock --user admin --reset   
      4. For Product version Protection & Recovery 9.x use the below,

        1. Launch the Web Console for the site recovery appliance.

        2. Log in as the root user.

        3. Execute the following command to check the lock status: faillock --user admin

        4. Reset the lockout counter for the admin account: /sbin/faillock --user admin --reset

        5. Verify the counter is cleared: faillock --user admin

        6. Authenticate to the VAMI using the admin account to confirm access is restored.

     4. At the command prompt, unmount the file system using the below command

  umount /

     5. Reboot the appliance     reboot -f 

     6. After the VLSR appliance reboots, log in with the new root password

Additional Information