I thought I share this quick tidbit about the VCSA (vCenter Server Appliance) default password for the vCenter SSO Administrator account as I was just asked about it today and this was something I had research just earlier in the week. In the Windows version of vCenter SSO installation, users are prompted during the install to select a password for this account, you might have seen it show up as [email protected]. For the VCSA, vCenter SSO is already installed and you might be wondering what the default password is?
Well, the answer is ... there is no default password. During the installation process, there is a random password that is generated and once the installation is complete, the password is then immediately removed. This is a good thing from a security perspective, by not having a default password set. This account is not only a vCenter SSO Administrator but it also the only account that has access to the internal RSA IMS system. You should definitely go in and set a password for this account after setting up your VCSA which can only be done through the vSphere Web Client.
Here are the steps:
1. Click on the Administration tab on the left hand side of the vSphere Web Client navigation bar.
2. Next click on "SSO Users ad Groups" and you should see the admin user account.
3. Lastly, you just need to right click and edit the user or select the pencil icon and set a password for the admin user account. Be sure to use a strong password, as there is a password validation before the system accepts the change.
Big thanks goes out to Michael Haines for helping me track down this answer about the default (or not so default) password for the admin account on the VCSA.
Any way to script this while logged into an ssh session as root?
Ed Grigson says
Thanks for the post William, just ran into this while configuring SSO in vShield Manager 5.1.
Hi; nice article.
I am baffled. If there is no password to login to the web client interface for [email protected], how does initially log into the web client at all?
I've tried blank passwords and the root account's password, but to no avail.
My assumption is that I need to first get into SSO admin in order to assign rights to AD accounts, right?
As mentioned in the article "During the installation process, there is a random password that is generated and once the installation is complete, the password is then immediately removed."
You don't login as [email protected] when you first login, you will login using root. From there you could add additional local SSO users OR connect to directory source such as openLDAP or AD and set the appropriate permissions for others to login.
Phil P says
I have lost my access to vCenter and hosts when logging to Web Client with AD account. I see everything with Root, recking my brain... My servers took a hard shutdown do to power outage.
Lewis Bowman says
Does this still apply to VCSA 5.5, since the *protected email* is now privileged automatically with SSO ?
William Lam says
Well this is no longer required as the default password for *protected email* is vmware, but you still may want to go in and change it from the default.
Can we query the embedded DB , if so which user/password to use ?
William Lam says
Take a look at http://www.virtuallyghetto.com/2012/11/vcsa-vcenter-server-appliance-51-vcdb.html
You can also find all my VCSA resources here http://www.virtuallyghetto.com/vcsa
Do you know how to reset the *protected email* password on 5.1? the only article i can find is this using the vdcadmintool - but this directory doesnt exist in 5.1 on my vcenter server.
William Lam says
I don't. For this, I would recommend contacting VMware GSS, they should be able to help with this request.
what is the difference between vSphere.local vs system.domain