Root Password Vaulting

Root Password Vaulting is a feature that allows CloudControl to manage the root password of individual hosts. For each host, the user can select the ‘Root Password Vaulting’ checkbox on the General tab when adding or editing hosts—see Modifying Managed Hosts. CloudControl will create a new secure root password on the selected host and store it in a password ‘vault’. CloudControl automatically rotates or updates the root password on the host on a regular basis (as specified by the Host Password Update scheduled event—see Scheduled Events).

An Enterprise or appropriate evaluation license is required to implement this feature.

CloudControl only supports Root Password Vaulting for ESXi 4.1 update 1 or later hosts. For unsupported ESXi hosts, if the host becomes inaccessible (as determined by assessment or some other host operation that repeatedly caused a connection or credential error), the recommended user action is to remove the host and add it back to CloudControl.

Important: We recommend that you export all log files to a SIEM or syslog tool to insure the RPV logs and hashes are exported and not stored in CloudControl.

If CloudControl becomes unavailable contact HyTrust Support.

Privileges

The following privileges are associated with Root Password Vaulting:

 

 

Asc.RootPasswordVaulting.Administration

Allocated to the ASC_ESXMAdmin and ASC_SuperAdmin Roles. Those Roles can configure Recovery Password and enable or disable RPV.

Asc.RootPasswordVaulting.PasswordRequest

Allocated to the ASC_VIAdmin, ASC_ESXMAdmin and ASC_SuperAdmin Roles. These Roles can issue passwords or cancel passwords for RPV enabled ESXi hosts.

Prerequisites

Perform the following before enabling Root Password Vaulting: