cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
800
Views
12
Helpful
12
Replies

Recover lost CCMAdminstrator password in CM4.0

swharvey
Level 3
Level 3

How can the CCMAdministrator password be reset if the original password is not known/lost? We have tried the ccmpwdchanger utility as well as the CM Admin Utility but neither application resets the CCMAdministrator user password. Can it be changed within the registry or via another method? Cisco documentation only shows how to reset the password in CM5.0, or in CM4.x but only after you are already logged into the CM Webadmin as the CCMAdministrator, which we cannot do. :(

Thanks

1 Accepted Solution

Accepted Solutions

Okay, we have some progress now. The CCMAdministrator account is stored on the Directory (DC or AD) so you are not going to have an account there. Please do as follows:

Go to user >> Global Directory and look for the CCMAdmin user and change that user's password.

Also in order to change the MLA password, please go to User >> Access Rights >> Configure MLA parameters, set the Enable MultiLevelAdmin to True, now you will see the "New Password for CCMAdministrator" & "Confirm password for CCMAdministrator" boxes, enter the new CCMAdmin password and click the Update button. Please restart the IIS service after this (just issue an IISreset command) .

Hope this helps!!!

View solution in original post

12 Replies 12

gogasca
Level 10
Level 10

In CCM 4.X MLA is builtin, you can enable it or disable it accesing directly into the DB.

SQL | Enterprise Manager | CCM03XX | MLAParameter | EnableMLA set it to F (False).

Then restart IIS.

Then open CCMAdmin again but using Administrator then enable MLA and configure the new password.

cybrsage
Level 1
Level 1

"Recovery of a Lost Cisco CallManager Administration Account Password

Because the Cisco CallManager Administration account is the Windows 2000 Server Local Administrator Account, there is no method available for recovering this password."

http://www.cisco.com/warp/public/788/AVVID/ics-password.html#topic7

I assume the same is applicable for the Linux version (ver 5).

espereir
Level 5
Level 5

Actually, there is a way to reset the Admin password on CCM 5 (Linux), I am looking for the information right now, I will send it as soon as I get it.

espereir
Level 5
Level 5

Finally, I found the document that I was looking, of course you need console access (not SSH or web), and the media as well, please check it here:

Step 1 Log in to the system with the following username and password:

?Username: pwrecovery

?Password: pwreset

The Welcome to admin password reset window displays.

Step 2 Press any key to continue.

Step 3 If you have a CD or DVD in the disk drive, remove it now.

Step 4 Press any key to continue.

The system tests to ensure that you have removed the CD or DVD from the disk drive.

Step 5 Insert a valid CD or DVD into the disk drive.

The system tests to ensure that you have inserted the disk.

Step 6 After the system verifies that you have inserted the disk, you get prompted to enter a new Administrator password.

Note The system resets the Administrator username to admin. If you want to set up a different Administrator username and password, use the CLI command set password.

Step 7 Reenter the new password.

The system checks the new password for strength. If the password does not contain enough different characters, you get prompted to enter a new password.

Step 8 After the system verifies the strength of the new password, the password gets reset, and you get prompted to press any key to exit the password reset utility.

Here is the link: http://www.cisco.com/en/US/partner/products/sw/voicesw/ps556/products_administration_guide_chapter09186a008063607d.html#wp1040303

espereir
Level 5
Level 5

Also, did you check if you are using MLA, if you have it running, please set the flag to F and then restart the IIS. After that, just login with the Windows Administrator account.

If the CCM is integrated with AD, you can reset the password of the CCMAdmin account on your domain and if it is DC Directory, we will need to disable MLA and then change it through the user page.

Okay, so we are running CM4.02sr2c, so the MLA is built-in. We tried the suggestion of changing the SQL MLAEnable parameter to F (without restarting SQL) on the Publisher, then stopping and restarting the IIS and WWW services. We logged into the CMAdmin using the local Windows Administrator account (which has full local administrator rights). We then went to Users->Acess Rights->Configure MLA Parameters and got the following error:

Error Please use a valid username or password.

This is a fresh install for a BARS migration from IBM to HP. We have not yet restored any data because we need the password for the CCMAdministrator account.

With this said:

1) What would cause the local windows administrator to not be a valid user for the CMAdmin MLA page?

2) Does a local windows CCMAdministrator account to exist on the Publisher (currently it does not)?

3) Where specifically in the CCAdmin MLA configuration is the setting to change the CCMAdministrator password once we successfully log in with the Windows local Admin account?

Thanks

Okay, we have some progress now. The CCMAdministrator account is stored on the Directory (DC or AD) so you are not going to have an account there. Please do as follows:

Go to user >> Global Directory and look for the CCMAdmin user and change that user's password.

Also in order to change the MLA password, please go to User >> Access Rights >> Configure MLA parameters, set the Enable MultiLevelAdmin to True, now you will see the "New Password for CCMAdministrator" & "Confirm password for CCMAdministrator" boxes, enter the new CCMAdmin password and click the Update button. Please restart the IIS service after this (just issue an IISreset command) .

Hope this helps!!!

To update, I followed your instructions and got the password rest prompts for CCMAdministrator. Here's where it gets odd. Clicking update the CMAdmin page stated that it successfully updated the password, and that the Web browser and IIS services needed to be restarted. After doing these things, the CCMAdministrator user password still did not. So we dug into the registry on the CM pub and found that there was no password entry for the key!

So we ran the passwordutils utility and generated the encrypted password and cut and pasted it into the registry. BAM! We were now able to access the CMWebadmin using the CCMAdminsitrator account.

But wait! It gets even more strange.....

Next we ran the 4.1.3 upgrade CD which completed with no errors. After rebooting the server, we attempted to log into the CMWebadmin with CCMAdministrator and could not. We checked the registry key again for the encrypted CCMAdministrator and it was gone! We again copied the encrypted password from the passwordutils application into the registry but it did not work this time. :(

Any thoughts on this odd problem?

Thx

espereir
Level 5
Level 5

Hi buddy,

Please foolw again that procedure that I have sent you, then try to change the registry key and restart the IIS, for some reason, CCM is not taking the settings.

Also, let me check on my CCM.

Thanks, we are in our maintenance window at the moment but I will check it when I can. I think it is possible that when you reinstalled the Directory Configuration Plugin, somehow the password registry entry gets erased for CCMAdministrator. This also is the case for CCMSysuser and IPMASysuser. I'll let you know when I try this again.

Okay, the description in AD for the CCMAdministrator was CiscoPrivateUser, so this account was not showing when I did a search under User Global Directory for CCMAmin. Once I changed the description in AD and reran the search, I was able to see the CCMAdministrator user, however, there is no option to reset the User Password (or any user p/w within CM). Could this be because the DIRACCESS value in the Directory Configuration Key in the registry is set to false?

Thanks for your continued assistance, this is a tough one for us.

Okay we finally got it! Here's the answers: When you uninstall/reinstall the Directory Configuration Utiliy, it wipes out the encrypted password for CCMUser, CCMAdministrator, and IPMAUser. We had to run the passwordutility program in DOS to make an encrypted password, then paste it into the registry. Our TAC engr had us try the PasswordChanger Utility, but it would not work and here is why: Our OU= and CN= and DC= were not the default. Instead of CCM users in AD being in the Users container(default), they were in a container called "Departments" which the PasswordChanger Utility did not pick up because it uses the preconfigured OU, CN, and DC values.

Once we changed the OU, CN, and DC locations on the CM, the users successfully authentcated via LDAP to AD and we were able to log in to the CM as CCMAdminstrator, and fixed other problems!

Ugggh the problems you run into when you inherit systems with no documentation.

I hope this helps others