VMware Cloud Community
tadduci
Contributor
Contributor

VMWare 6.5 - changed DCUI user password

What are the ramifications and remediation steps required if a production VMWare server had the DCUI password changed in the VSphere client when administrating a VMWare 6.5 server? A colleague trying to determine the root cause for a system restart suspected that the system was hacked and changed this password using the VSphere client software and successfully changed the DCUI user account after the system restarted.

Thank you.

Tony

0 Kudos
5 Replies
virtualg_uk
Leadership
Leadership

Hi Tony,

Changing the password via DCUI does not require a reboot. I have validated this in ESXi 6.5 for you but I recall the same for v5.x


Graham | User Moderator | https://virtualg.uk
0 Kudos
tadduci
Contributor
Contributor

It's not so much of a question regarding if it requires a reboot as it is this was a mistake and now what can I do about it and what are the downsides of this accidental change?

In other words, changing the password of the DCUI account can cause what harm and when?

How do I fix this and make it so the system will perform as it did prior to the change or during a restart if this is a systems account?

Thanks.

Tony

0 Kudos
virtualg_uk
Leadership
Leadership

I think I misunderstood you question there.

The root account password can be changed without reboot..

BUT the DCUI password should not be changed or removed. This is a service account used by ESXi and vCenter server for various reasons. One being to integrate with lockdown mode. USers should not be logging in with this account.

If you have changed the DCUI password (and not the root password) then personally I would be looking at re-installing ESXi to ensure this goes back to normal and nothing else has been tampered with.

Failing that, I would log a support request with VMware unless someone else is able to assist?


Graham | User Moderator | https://virtualg.uk
0 Kudos
tadduci
Contributor
Contributor

Yes, I realize that it shouldn't be changed so now I am just trying to figure out how to best proceed from here.

I didn't change it but I am trying to clean up after the fact.

No users were using this account. The coworker changed it as a precaution.

Tony

0 Kudos
virtualg_uk
Leadership
Leadership

Hi Tony

I totally understand now. So, I would perform a fresh install to ensure that this does not have any further issues down the line. I do not think there is a "restore DCUI" user as such I'm afraid.

This might help with that process: How to back up ESXi host configuration (2042141) | VMware KB


Graham | User Moderator | https://virtualg.uk
0 Kudos