由於多次嘗試登入失敗,一或多個 ESXi 主機的根帳戶遭到鎖定。
無法使用 SSH 或 Web UI 連線至節點。
使用 iDRAC 主控台向 ESXi shell 確認問題。
在 vCenter 中,會顯示類似以下內容的警告訊息:
Remote access for ESXi local user account 'root' has been locked for 900s after 14 failed login attempts.
圖 1:遠端存取已鎖定。
您會在受影響的主機上看到類似以下的記錄:
/var/log/vobd.log
2020-04-03T17:27:58.790Z: [GenericCorrelator] 8202447897096us: [vob.user.account.locked] Remote access for ESXi local user account 'root' has been locked for 900 seconds after 32 failed login attempts.
2020-04-03T17:27:58.790Z: [UserLevelCorrelator] 8202447897096us: [vob.user.account.locked] Remote access for ESXi local user account 'root' has been locked for 900 seconds after 32 failed login attempts.
2020-04-03T17:27:58.791Z: [UserLevelCorrelator] 8202447897325us: [esx.audit.account.locked] Remote access for ESXi local user account 'root' has been locked for 900 seconds after 32 failed login attempts.
/var/log/auth.log
2020-04-03T17:29:06Z sshd[701694298]: Connection from 192.168.100.40 port 55682
2020-04-03T17:29:06Z sshd[701333862]: pam_tally2(sshd:auth): user root (0) tally 34, deny 5
2020-04-03T17:29:08Z sshd[701694298]: error: PAM: Authentication failure for root from 192.168.100.40
2020-04-03T17:29:08Z sshd[701694492]: pam_tally2(sshd:auth): user root (0) tally 35, deny 5
2020-04-03T17:29:08Z sshd[701694492]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=192.168.100.40 user=root
2020-04-03T17:29:10Z sshd[701694298]: error: PAM: Authentication failure for root from 192.168.100.40
2020-04-03T17:29:10Z sshd[701694298]: error: Received disconnect from 192.168.100.40 port 55682:3: com.jcraft.jsch.JSchException: Auth cancel [preauth]
2020-04-03T17:29:10Z sshd[701694298]: Disconnected from authenticating user root 192.168.100.40 port 55682 [preauth]
Cntrl-Alt-F1
以訪問外殼。#pam_tally2 --user root #pam_tally2 --user root --reset #pam_tally2 --user root
如需詳細資訊,請參閱 VMware 文章 ESXi 密碼和帳戶鎖定。
觀看此影片:ESXi 損壞修復解鎖 root 使用者帳戶。
持續時間:00:04:56 (小時:分鐘:秒)
當可用時,您可以使用此影像播放器上的設定或 CC 圖示來選擇隱藏式輔助字幕 (字幕) 語言設定。
相關資源
以下是一些可能感興趣的與本主題相關的建議資源: