To improve the security posture of the system, you must change passwords for the accounts that are used by your VMware Cloud Foundation instance. Changing these passwords periodically or when certain events occur, such as an administrator leaving your organization, reduces the likelihood of security vulnerabilities.
You perform password rotation using several different methods and procedures, depending on the account type and the component of your VMware Cloud Foundation instance.
For example, if you change the password of the Active Directory binding service account, you must reconfigure the integration between Active Directory and your VMware Cloud Foundation instance.
Component |
Account |
Procedure |
---|---|---|
SDDC Manager |
root |
|
vcf |
||
backup |
||
admin@local |
||
ESXi |
root |
|
vCenter Server |
root |
|
vCenter Single Sign-On |
||
Identity Source (LDAP) Bind User |
|
|
NSX Local Manager |
root |
|
admin |
||
audit |
||
NSX Edge Node |
root |
|
admin |
||
audit |