<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: admin password reset back to default? bug? in Security</title>
    <link>https://community.splunk.com/t5/Security/admin-password-reset-back-to-default-bug/m-p/333203#M8505</link>
    <description>&lt;P&gt;How did you do the upgrade? tar? rpm?&lt;/P&gt;

&lt;P&gt;Like Muebel said, my guess is etc/passwd got moved or overwritten&lt;/P&gt;</description>
    <pubDate>Tue, 18 Apr 2017 13:51:27 GMT</pubDate>
    <dc:creator>mattymo</dc:creator>
    <dc:date>2017-04-18T13:51:27Z</dc:date>
    <item>
      <title>admin password reset back to default? bug?</title>
      <link>https://community.splunk.com/t5/Security/admin-password-reset-back-to-default-bug/m-p/333201#M8503</link>
      <description>&lt;P&gt;I have three indexers in a cluster. We're in the process of taking them offline, in turn, for updates. They are running 6.5.1, we are updating them to 6.5.3. &lt;/P&gt;

&lt;P&gt;So, I go to take the first one offline and the admin password does not work. On a whim, I tried the default "changeme" and it worked! The last time we did an update it went from 6.5.0 to 6.5.1. Those are the facts, but the assumption is that it got reset when updating to 6.5.1...?&lt;/P&gt;

&lt;P&gt;I've been using Splunk for a half-dozen years, and never seen it reset it's admin password back to default...&lt;/P&gt;

&lt;P&gt;Thoughts? Bug? Or, just another one of those snowflake things at my site that no one else has ever seen?   &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Michael&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2017 13:29:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/admin-password-reset-back-to-default-bug/m-p/333201#M8503</guid>
      <dc:creator>Michael</dc:creator>
      <dc:date>2017-04-18T13:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: admin password reset back to default? bug?</title>
      <link>https://community.splunk.com/t5/Security/admin-password-reset-back-to-default-bug/m-p/333202#M8504</link>
      <description>&lt;P&gt;Hi Michael,&lt;/P&gt;

&lt;P&gt;The admin passwd can get set to default if the etc/passwd file in splunk's installation directory is cleared. Perhaps this is what happened?&lt;/P&gt;

&lt;P&gt;Past that, my only readily available explanation is that it was never set to begin with. &lt;/P&gt;

&lt;P&gt;If neither of these fit, yeah, file a P4 with support and see if they have any advice.&lt;/P&gt;

&lt;P&gt;Please let me know if this answers your question! &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2017 13:38:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/admin-password-reset-back-to-default-bug/m-p/333202#M8504</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2017-04-18T13:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: admin password reset back to default? bug?</title>
      <link>https://community.splunk.com/t5/Security/admin-password-reset-back-to-default-bug/m-p/333203#M8505</link>
      <description>&lt;P&gt;How did you do the upgrade? tar? rpm?&lt;/P&gt;

&lt;P&gt;Like Muebel said, my guess is etc/passwd got moved or overwritten&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2017 13:51:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/admin-password-reset-back-to-default-bug/m-p/333203#M8505</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-04-18T13:51:27Z</dc:date>
    </item>
    <item>
      <title>Re: admin password reset back to default? bug?</title>
      <link>https://community.splunk.com/t5/Security/admin-password-reset-back-to-default-bug/m-p/333204#M8506</link>
      <description>&lt;P&gt;Ah, that may be it, the sys-admin for the box is using Salt... when check and get back...&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2017 13:54:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/admin-password-reset-back-to-default-bug/m-p/333204#M8506</guid>
      <dc:creator>Michael</dc:creator>
      <dc:date>2017-04-18T13:54:43Z</dc:date>
    </item>
  </channel>
</rss>

