"Orchestrator Blues" Part 2: VCO and VCG password traps and recovery actions
When you set up new Orchestrator and Gateways it typically takes some time until you need to relogin via SSH or via Console in order to do for example an upgrade to a new version.
Default password expiration is typically set to 90 days.
Normally when for an account the password is expired you still can login via console and specifiy a new password afterwards.
Unfortunately VMware SD WAN Orchestrator and Gateways have a specific setting, that completely disables login of vcadmin after the first 90 days without any password change even on console.
In that case you are left with unreachable VCO and VCGs regarding CLI.
So the only way to overcome is a password reset procedure:
And there are as far as I have seen, 2 ways to do such a password reset:
- Password Reset via GRUB Recovery Mode
- Reconnect of Disk to separate Unix System and doing Password Reset from there
As the first method is much simpler you should always try that one, before using the 2nd one.
WARNING: Be careful and have a Snapshot or backup done before attempting the following procedures, the author takes no responsibility for the correctness of the following commands and sequences.
Password Reset via GRUB Recovery Mode
Reconnect of Disk to separate Unix System and doing Password Reset from there
Both methods presented allow you to continue without needed to reapply and reconfigure the whole device.
Comments
Post a Comment