<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Scripted password change in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Scripted-password-change/m-p/112173#M23768</link>
    <description>&lt;P&gt;We have 20+ cmode clusters spread across the Enterprise. &amp;nbsp;Has anyone came up with a way to change admin passwords using some form of scripting. &amp;nbsp;On 7mode we used to used DFM to coordiate the password change across the globe. &amp;nbsp;However with Cmode we have not come up with a way to change the passwords easily without connecting to each machine. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our requirements are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Must be auditable, we must provide proof of password change success (We use command log)&lt;/P&gt;&lt;P&gt;we are talking the cluster admin, not vserver admin&lt;/P&gt;&lt;P&gt;We do the change every 30 days.&lt;/P&gt;&lt;P&gt;We run it on 20+ clusters.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The entire environment is Cmode Ontap 8.3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Throwing this out here so I dont have to recreate the wheel.&lt;/P&gt;</description>
    <pubDate>Wed, 04 Nov 2015 20:28:36 GMT</pubDate>
    <dc:creator>mrcwillis</dc:creator>
    <dc:date>2015-11-04T20:28:36Z</dc:date>
    <item>
      <title>Scripted password change</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Scripted-password-change/m-p/112173#M23768</link>
      <description>&lt;P&gt;We have 20+ cmode clusters spread across the Enterprise. &amp;nbsp;Has anyone came up with a way to change admin passwords using some form of scripting. &amp;nbsp;On 7mode we used to used DFM to coordiate the password change across the globe. &amp;nbsp;However with Cmode we have not come up with a way to change the passwords easily without connecting to each machine. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our requirements are:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Must be auditable, we must provide proof of password change success (We use command log)&lt;/P&gt;&lt;P&gt;we are talking the cluster admin, not vserver admin&lt;/P&gt;&lt;P&gt;We do the change every 30 days.&lt;/P&gt;&lt;P&gt;We run it on 20+ clusters.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The entire environment is Cmode Ontap 8.3.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Throwing this out here so I dont have to recreate the wheel.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 20:28:36 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Scripted-password-change/m-p/112173#M23768</guid>
      <dc:creator>mrcwillis</dc:creator>
      <dc:date>2015-11-04T20:28:36Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted password change</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Scripted-password-change/m-p/112182#M23771</link>
      <description>&lt;P&gt;Since we don't have that many clusters, we still do ours by hand, so, in that sense, I have nothing to help you with here (You're welcome!) other than to say I'd probably write something in `expect` to do it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Though, for the paranoia level of 'every 30 days' demonstrates, there's probably a lot of changes you'd want to do.&lt;/P&gt;&lt;P&gt;* change admin's password&lt;/P&gt;&lt;P&gt;* audit the allowed keys against an external key repo&lt;/P&gt;&lt;P&gt;* change diag's password&lt;/P&gt;&lt;P&gt;* change DFM/oncommand's password&lt;/P&gt;&lt;P&gt;* change VSC's password (if applicable)&lt;/P&gt;&lt;P&gt;* change the cluster switch passwords&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 22:45:47 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Scripted-password-change/m-p/112182#M23771</guid>
      <dc:creator>FULLSTEAM</dc:creator>
      <dc:date>2015-11-04T22:45:47Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted password change</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Scripted-password-change/m-p/112184#M23772</link>
      <description>&lt;P&gt;Via powershell or WFA ...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;every 30 days is kind of crazy...I assume you only mean the admin account&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 23:49:38 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Scripted-password-change/m-p/112184#M23772</guid>
      <dc:creator>JGPSHNTAP</dc:creator>
      <dc:date>2015-11-04T23:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted password change</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Scripted-password-change/m-p/155583#M35054</link>
      <description>&lt;P&gt;how to set this up with the WFA tool?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 08:47:05 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Scripted-password-change/m-p/155583#M35054</guid>
      <dc:creator>Stefan_K</dc:creator>
      <dc:date>2020-04-16T08:47:05Z</dc:date>
    </item>
  </channel>
</rss>

