Workload Automation

 View Only

Tech Tip: Reset Missing or Forgotten EiamAdmin Password in EEM 12.x 

Sep 23, 2015 02:14 PM

The below document describes how to reset the EiamAdmin password if it is missing or forgotten, on Windows and non-Windows platforms.


Access to the itechpoz DSA is required, so the current security for this DSA needs to be modified and then have the itechpoz DSA restarted.

  • Open the file /opt/CA/SharedComponents/CADirectory/dxserver/config/access/itechpoz.dxc (C:\Program Files (x86)\CA\Directory\dxserver\config\access\itechpoz.dxc on Windows)
    • Change "set access-controls = false;"
  • Save this file
  • Open the file /opt/CA/SharedComponents/CADirectory/dxserver/config/settings/itechpoz.dxc (C:\Program Files (x86)\CA\Directory\dxserver\config\settings\itechpoz.dxc on Windows)
    • Change "set min-auth = none;"
  • Save this file
  • Open the file /opt/CA/SharedComponents/CADirectory/dxserver/config/knowledge/itechpoz.dxc (C:\Program Files (x86)\CA\Directory\dxserver\config\access\itechpoz.dxc on Windows)
    {
    item 2, highlighted below in green, is required on non-Windows EEM servers}
    • Change "set auth-levels = anonymous"
    • Change "address = ipv4 "<IP address>" port 509, ipv4 "<hostname>" port 509"
  • Save this file
  • Reinitialize itechpoz DSA from command line using su - dsa -c "dxserver init all" (restart DXserver_itechpoz service on Windows)
  • Install and run any ldap browser on your EEM server. We normally recommend JXplorer 3.2.2 or higher (available at www.jxplorer.org)
    • Connect to the itechpoz DSA using your EEM server information.
      jxplorer1.png
    • Save this template for future use if you like.
    • Once connected follow the tree down to the EiamAdmin ID noted in the screenshot below:
      jxplorer2.png
    • Double-click on the userPassword value and enter in the new password and then re-enter to confirm.
    • Click OK then click Submit

You can now check that the password in the EEM UI for the EiamAdmin account is working.

Statistics
0 Favorited
25 Views
0 Files
0 Shares
0 Downloads

Tags and Keywords

Comments

Oct 12, 2015 10:55 AM

Grant,

 

I get why it was done. I was just pointing out the wisdom of it. I am speaking purely from an InfoSec ideology, and nothing else. I for one would rather this get answered in a trouble ticket this way there's a paper trail of the ask and answer. I am glad the misprint is fixed.. And yes maybe we have people that would never think of creating a back door to the security, but unfortunately I have seen and heard of it happening. Thus my comment.

 

Thank you for understanding my point. Once again thank you for the update on the tip.

 

Steve C.

Oct 12, 2015 10:47 AM

Steve,

 

This post was written with the intent to ensure that the most accurate information available regarding the subject matter has the widest reach.  This has been available via TECDOCs for years, but there was a correction that needed to take place, hence teh green highlighting in the article above.

 

Thank you for your feedback.

 

Regards,

Grant

Oct 12, 2015 08:21 AM

Call me paranoid, But I always felt this is one of those TIPS that should NOT be posted. why?!

In case we have a normal user or an SA on here that may decide, he will do this because he absolutely needs to gain access...

that's just my 3 cents on it.

 

Steve C.

Related Entries and Links

No Related Resource entered.