Local Administrator Password Change Triggers a Commit Lock

Local Administrator Password Change Triggers a Commit Lock

21982
Created On 09/26/18 13:49 PM - Last Modified 06/15/23 21:24 PM


Environment


  • Palo Alto Firewall.
  • Any PAN-OS.


Cause


Changing the local administrator's password changes the configuration. The password hash is part of the configuration. If the user decides to diff the configuration the phash field has changed. The password change takes effect immediately, but on each commit, linux passwords are updated from the phash value. Users can change passwords and have them take effect in templates or HA.

Resolution


Overview

With the 'Automatically Acquire Commit Lock' option checked, changing the password of a local administrator without a commit operation triggers a commit lock. See the following example.

 

Steps

  1. Create a local administrator, a superuser.
    Username: abc
    Password: abc
  2. Make sure the 'Automatically Acquire Commit Lock' option is checked under GUI: Device > Setup > Management > General Settings.
  3. Commit the configuration.
  4. Login into the device with an administrator other than ''abc.'' Login using admin/admin for credentials.
  5. Change the password for username 'abc' to xyz and click OK, but do not commit.
  6. Open a different browser and log into the firewall using these credentials:
    username: abc
    password: xyz                           <<< new password

    Note: The administrator will be able to successfully login using the new password 'xyz'.

 

Follow the steps below to remove the commit lock:

  1. Click on the lock icon:
    Screen Shot 2015-01-15 at 5.32.46 PM.png
     
  2. In the window that appears, select "admin" and click on "remove lock" at the bottom and then click on "OK"
    Screen Shot 2015-01-15 at 5.34.47 PM.png
     
  3. Commit the changes.

 

 

 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClrSCAS&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language