跳转到主内容

在 CVO 中进行安全强化后,代理继续使用旧的管理员凭据

Views:
95
Visibility:
Public
Votes:
0
Category:
cloud-manager
Specialty:
cloud
Last Updated:

适用于

  • NetApp Cloud Volumes ONTAP (CVO)
  • NetApp Console Agent (NetApp Console Connector)
  • 具有安全强化功能的 CVO 版本(锁定了默认管理员用户)

问题

在 Cloud Volumes ONTAP (CVO) 上完成安全强化并 创建新的管理员用户后,NetApp Console Agent 继续尝试使用旧的、现在已锁定的默认管理员帐户进行连接。
  • CVO 上的安全审核日志显示使用管理员帐户从 Console Agent VM IP 进行的重复失败登录尝试。
  • SIEM 和警报工具充斥着与锁定的管理员账号相关的身份验证失败。
  • NetApp Console 界面看起来很健康;CVO 通过新的管理员用户重新发现。
  • 日志输出示例:Failed login attempt for user 'admin' from IP 10.91.247.2

原因

NetApp Console Agent 在其内部数据库中保留旧的管理员凭据,并继续使用它们进行集群身份验证,即使在使用新的管理员用户重新发现 CVO 之后也是如此。如果集群管理员帐户被更改或锁定,代理不会自动清除或更新凭据。

解决方案

部署新的 NetApp Console 代理,并使用新的管理员凭据重新发现 CVO。
  • 停用旧代理。
  • 部署新代理。
  • 使用新管理员凭据在工作区中重新发现 CVO 实例。

合作伙伴备注

合作伙伴备注文本

追加信息

追加信息文本

内部参考

内部参考文本

Sign in to view the entire content of this KB article.

New to NetApp?

Learn more about our award-winning Support

NetApp provides no representations or warranties regarding the accuracy or reliability or serviceability of any information or recommendations provided in this publication or with respect to any results that may be obtained by the use of the information or observance of any recommendations provided herein. The information in this document is distributed AS IS and the use of this information or the implementation of any recommendations or techniques herein is a customer's responsibility and depends on the customer's ability to evaluate and integrate them into the customer's operational environment. This document and the information contained herein may be used solely in connection with the NetApp products discussed in this document.