VMware Cloud Community
JLogan2016
Enthusiast
Enthusiast

Best practices for administrator@vsphere.local password

I ran into an issue recently where we were unable to remove a PSC in preparation for a 6.5 upgrade. A call to VMware resulted in finding out that it was due to a semi-colon in the local admin password (said password has been in place for a couple of years at this customer, and never any other issues, so I am skeptical). I am planning on changing the password to test, and have been looking about for guidance on best practices. The only thing I can find in the VMware docs is this:

vCenter Server Password Requirements and Lockout Behavior

which states

The password for administrator@vsphere.local must meet the following requirements:

  • At least 8 characters
  • At least one lowercase character
  • At least one numeric character
  • At least one special character

The password for administrator@vsphere.local cannot be more than 20 characters long. Only visible ASCII characters are allowed. That means, for example, that you cannot use the space character.

So A: it mentions nothing about a semi-colon causing issues, and B) it concerns me as we go to plan a new password. Having a security background, I tend toward pass-phrases more than passwords, so I would do something along the lines of vSphere Let Me In1! but now I am concerned about the spaces. Does anyone know of any other KBs or docs that shed more light on this?

0 Kudos
2 Replies
LokeshHK
VMware Employee
VMware Employee

Please look in to below KB Installing vCenter Single Sign-On 5.5 fails if the password for administrator@vsphere.local contains...

which talks about similar issue.

Regards

Lokesh

0 Kudos
JLogan2016
Enthusiast
Enthusiast

Thanks, I did see this, but it specifically states the issue is resolved in 5.5a (except for the ! character). I was hoping someone had experience in whether it was completely resolved by the time we got to 6.5.

0 Kudos