Data Domain: How to Reset Sysadmin or Security Officer Password
Summary: Data Domain sysadmin/SO password resets no longer require Support intervention when running DDOS (7.10.1.40 or newer). A password reset token is sent to the registered email address. Copy the token to a supported USB drive, insert it into the system, and log in as sysadmin or security officer to reset the password. ...
Acest articol se aplică pentru
Acest articol nu se aplică pentru
Acest articol nu este legat de un produs specific.
Acest articol nu acoperă toate versiunile de produs existente.
Instructions
Data Domain sysadmin or Security Officer (Secoff | SO) accounts requiring a password reset no longer require Tech Support intervention.
Note: This process is considered administrative; any request for onsite support is chargeable on a Time and Materials (T&M) basis.
Limitations:
- This method of password reset does not apply to DDVE and DDMC; for those, contact Tech Support.
- The DD3300 model doesn't support this method either as it is a DDVE system.
- DO NOT reset passwords on a DD Highly Available (HA) system in a DEGRADED state.
- Sysadmin and SecOff accounts cannot be reset using the Web-UI (DD System Manager)
Prerequisites:
- DDOS version 7.10.1.40 | 7.13.1.10 | 8.3.x… (or newer)
- SSH or Serial Console access
- Preset recovery email address (# user recovery-email set <email address>)
- USB-Drive (Any Size: Formatted as FAT32, ext2, ext3, ext4, MSDOS, or iso9660)
- Physical access to the Data domain to insert the USB-Drive
Password Reset Procedure:
- After 3x failed login attempts using CLI (SSH or Serial Console), the system will display an error: "Too many authentication failures" and the session is disconnected.
ssh -l sysadmin datadomain
(sysadmin@datadomain) Password: <attempt1>
(sysadmin@datadomain) Password: <attempt2>
(sysadmin@datadomain) Password: <attempt3>
Received disconnect from <IP> port 22: Too many authentication failures
Disconnected from <IP>
- Immediately RE-ESTABLISH the CLI connection, and the 'reset password' prompt appears; Enter 'Yes' to reset the password when prompted.
# ssh -l sysadmin <datadomain>
Data Domain OS
(sysadmin@datadomain) Do you want to reset password [ yes | no ] ? yes
Password reset token is sent to registered email address: <s****e@somewhere.com>
- An email containing a token file <recovery_token.txt> is sent to the 'recovery email' account.
- Copy the <recovery_token.txt> file in the email to a USB drive, ensuring the filename remains unchanged. Supported filesystems for USB are FAT32, ext2, ext3, ext4, MSDOS, and iso9660.
- Insert the USB drive into any available USB port on the affected PowerProtect DD System.
- Log in as sysadmin or security officer to access the PowerProtect DD CLI and follow the prompts to reset the sysadmin or security officer password.
Recovery Example: USB-Drive plugged in with valid Token file.
# ssh -l sysadmin <datadomain>
Data Domain OS
Do you want to reset password [ yes | no] ? yes
USB drive with valid token is found. (**)
Enter new password:
Re-enter new password:
sysadmin password changed successfully.
Please remove USB with token.
(**) If a USB-Drive is NOT inserted (or has an invalid token) then a new Token gets generated by the recovery script (as seen in Step 2.)
NOTE:
- A password reset token is single-use only and is valid for 24 hours.
- A new reset token can be created at any time, if needed (repeat Step 1 in the recovery process)
- The new password should match the password strength criteria.
- If an invalid token is copied to USB, the password reset fails.
- Rebooting the system invalidates any existing token.
- DO NOT reset passwords on a DEGRADED HA system.
- Password recovery does not work as expected if the System Management Service (SMS) is down; a reboot may recover that service.
Additional Information
References and Supplemental content:
- DDOS Admin or Command Reference Guides - Dell PowerProtect Data Domain Info Hub
- Data Domain: Connecting to the Data Domain System with a Serial Cable
The feature must have been configured BEFORE the password was lost or forgotten, using the command:
# user recovery-email set <email id>
To check if a recovery account is configured:
# user recovery-email show
Password recovery email address for sysadmin is: someone@somewhere.com
Produse afectate
Data Domain, DD OSProduse
Data Domain Deduplication Storage Systems, DD OS 7.10, DD OS 7.13, DD OS 8.3Proprietăți articol
Article Number: 000291519
Article Type: How To
Ultima modificare: 02 Sep 2025
Version: 5
Găsiți răspunsuri la întrebările dvs. de la alți utilizatori Dell
Servicii de asistență
Verificați dacă dispozitivul dvs. este acoperit de serviciile de asistență.