If the default password is used, a warning message is displayed to alert you about this security vulnerability. This message is displayed if:
The warning message is also displayed when you log in to the iDRAC using SSH, Telnet, remote RACADM, or the Web interface. For the Web interface, SSH, and Telnet, a single warning message is displayed for each session. For remote RACADM, the warning message is displayed for each command.
The default iDRAC username and password are widely known, and any user with access to the server could change the default password. The Default Password Warning feature in iDRAC warns you if the default login credentials are still in place.
Whenever a user with Configure User privileges logs in to iDRAC or SSH/Telnet or runs RACADM commands remotely using the default login credentials, the system displays a warning message (SEC0701). Because UI and SSH/Telnet users log in once per session, they see a single warning message for each session. Because remote RACADM users log in for every command, they see a warning message for every command.
An iDRAC with default login credentials is even less secure if the system is Internet-accessible or part of a large network with different trust boundaries.
For more information about iDRAC9, go to the iDRAC9 support pages, then select the iDRAC9 firmware version for documentation including the User's Guide for additional information. What is the default username and password for Integrated Dell Remote Access Controller (iDRAC)? explains the default username and password.
To improve security, it is recommended to use complex passwords that have eight or more characters and include lowercase alphabets, uppercase alphabets, numbers, and special characters. It is also recommended to change the passwords, if possible regularly.
Characters | Length |
---|---|
0 1 2 3 4 5 6 7 8 9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z a b c d e f g h i j k l m n o p q r s t u v w x y z - ! # $ % & ( ) * / ; ? @ [ \ ] ^ _ ' { | } ~ + < = > |
1 to 16 characters |
Characters | iDRAC Firmware Version | Length |
---|---|---|
0 1 2 3 4 5 6 7 8 9 A B C D E F G H I J K L M N O P Q R S T U V W X Y Z a b c d e f g h i j k l m n o p q r s t u v w x y z - ! # $ % & ( ) *, . / : ; ? @ [ \ ] ^ _ ' { | } ~ + < = > |
3.xx | 1 to 20 characters |
4.xx, 5.xx, and 6.xx | 1 to 40 characters | |
7.xx |
1 to 127 characters |
You may be able to create usernames and passwords that include other characters. However, to ensure compatibility with all interfaces, Dell Technologies recommends using only the characters listed here.
<
, >
, and ,
(comma).
When you log in to the iDRAC web interface, if the Default Password Warning page is displayed, you can change the password.
Figure 1: iDRAC9 default username and password warning message
Alternately, if the default password warning page is disabled:
Note:This procedure is also valid if the original password is lost.
Figure 2: System Setup Main Menu
Figure 3: iDRAC Settings
Figure 4: User Configuration
Figure 5: Change Password
Figure 6: Password changed
Figure 7: Clicking Finish
Figure 8: Warning to Save Changes
Figure 9: Settings saved confirmation
Figure 10: Clicking Finish
To change the password, run the following RACADM command:
racadm set iDRAC.Users.<INDEX>.Password <PASSWORD>
<INDEX>
= A value from 1 to 16 that indicates the user account<PASSWORD>
= The new user-defined password