Skip to content
Browse Gluu Server 4.5

Release

Change Admin Password

#Overview

There are times when default Gluu admin password need to be changed, for example rotating password for security reason.

#Change admin password in oxTrust

  1. Login to oxTrust UI as admin user (created during installation).
  2. Go to Users > Manage People sidebar menu, search for admin user in the form field. A list of matched users will be presented in a table.
  3. Click the admin UID in the results table.
  4. Scroll down and click Change Password button; a popup will be presented. Click Set password after password has been changed. If password successfully updated, the user will be logged out.

#Update Kubernetes secrets

Once admin password has been changed via oxTrust UI, the Kubernetes secrets need to be updated as well. See steps below on how to update the secrets:

  1. Change config.adminPass attribute in values.yaml for subsequential installs/upgrades using helm:

    config:
      # use same password that was updated in oxTrust
      adminPass: "newAdminPassword"
  2. Create new file update_admin_secrets.py with the following contents:

    from pygluu.containerlib import get_manager
    
    # get the value of `userPassword` attribute from `gluuPerson` table/objectClass/document in persistence
    encoded_oxtrust_admin_password = "<userPassword>"
    
    manager = get_manager()
    manager.secret.set("encoded_oxtrust_admin_password", encoded_oxtrust_admin_password)

    Note, the <userPassword> value is taken from userPassword attribute/column of gluuPerson table/document. Consult to persistence (MySQL/PostgreSQL/OpenDJ/Couchbase/Spanner) docs on how to get value of an attribute.

  3. Copy the update_admin_secrets.py to a running pod and execute:

    kubectl -n $NAMESPACE cp update_admin_secrets.py $POD:/tmp/update_admin_secrets.py

    Run the script to update the secrets:

    kubectl -n $NAMESPACE exec $POD -- python3 /tmp/update_admin_secrets.py