VMware Cloud Community
vAndrew
Enthusiast
Enthusiast

ESXi Root Password Complexity Issue

Hi,

We have recently deployed 2 new ESXi 6.5 hosts. One we have set as our default password and it works fine, the other refuses to accept the same password and complains its not complex enough. They are the same build

-- Andrew (VMware VCP-DCV, MCSA)
Reply
0 Kudos
6 Replies
dbalcaraz
Expert
Expert

Weird thing...

If you use the same ISO file then the same hypervisor is installed hence, it can't be possible what you said.

Are you accessing from an IPMI to each host?

-------------------------------------------------------- "I greet each challenge with expectation"
Reply
0 Kudos
Buddhika01
Contributor
Contributor

Reply
0 Kudos
vAndrew
Enthusiast
Enthusiast

It clearly can be possible though, hence this post?

The root password was blank initially, which I thought it wouldn't allow, but did. If I try and change it, I get it moaning about complexity, yet it didn't on the others.

I have tried to remove the complexity from the host using both the PAM file and also the advanced settings option, makes no difference, doesn't even seem to acknowledge anything has changed and still wont let me set the password to the lesser, but used everywhere password.

The same problem occurs no matter how I access it, both from DCUI and also the web client console of the host. Funny thing is, I believe this is the expected behaviour and its doing what its meant to be doing. But doesn't explain why the other one let me set it as I wanted it.

-- Andrew (VMware VCP-DCV, MCSA)
Reply
0 Kudos
vAndrew
Enthusiast
Enthusiast

First thing id tried, didn't make any difference, maybe I done it wrong, but cant really see how. Even tried the "new" way in 6.5 and used the advanced settings options as that way sort of replaces the need to edit this file manually, still doesn't work. Bloody annoying

-- Andrew (VMware VCP-DCV, MCSA)
Reply
0 Kudos
dbalcaraz
Expert
Expert

Ah, okay, so you didn't put your final password at the beggining when you install ESXi.

Did you make changes in the pam file and it doesn't work? Did you reboot the ESXi host after applying it?

Also, be aware that not all combinations work, check out more information: ESXi Passwords and Account Lockout

-------------------------------------------------------- "I greet each challenge with expectation"
Reply
0 Kudos
peetz
Leadership
Leadership

The password complexity rules are only enforced when you *change* the password. The new password will then be checked against the rules.

If a less complex password is already set when you change the rules then it will continue to work, because the password itself is never stored on the system (only a hash value) and thus cannot be checked once it was set.

May this explain the behavior that you are seeing?

Twitter: @VFrontDe, @ESXiPatches | https://esxi-patches.v-front.de | https://vibsdepot.v-front.de
Reply
0 Kudos