由于多次登录尝试失败,一个或多个 ESXi 主机的 root 帐户被锁定。
无法使用 SSH 或 Web UI 连接到节点。
使用 iDRAC 控制台到 ESXi shell 确认问题。
在 vCenter 中,将显示类似于以下内容的警告消息:
Remote access for ESXi local user account 'root' has been locked for 900s after 14 failed login attempts.
图 1:远程访问已锁定。
在受影响的主机上找到类似于以下内容的日志:
/var/log/vobd.log
2020-04-03T17:27:58.790Z: [GenericCorrelator] 8202447897096us: [vob.user.account.locked] Remote access for ESXi local user account 'root' has been locked for 900 seconds after 32 failed login attempts.
2020-04-03T17:27:58.790Z: [UserLevelCorrelator] 8202447897096us: [vob.user.account.locked] Remote access for ESXi local user account 'root' has been locked for 900 seconds after 32 failed login attempts.
2020-04-03T17:27:58.791Z: [UserLevelCorrelator] 8202447897325us: [esx.audit.account.locked] Remote access for ESXi local user account 'root' has been locked for 900 seconds after 32 failed login attempts.
/var/log/auth.log
2020-04-03T17:29:06Z sshd[701694298]: Connection from 192.168.100.40 port 55682
2020-04-03T17:29:06Z sshd[701333862]: pam_tally2(sshd:auth): user root (0) tally 34, deny 5
2020-04-03T17:29:08Z sshd[701694298]: error: PAM: Authentication failure for root from 192.168.100.40
2020-04-03T17:29:08Z sshd[701694492]: pam_tally2(sshd:auth): user root (0) tally 35, deny 5
2020-04-03T17:29:08Z sshd[701694492]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=192.168.100.40 user=root
2020-04-03T17:29:10Z sshd[701694298]: error: PAM: Authentication failure for root from 192.168.100.40
2020-04-03T17:29:10Z sshd[701694298]: error: Received disconnect from 192.168.100.40 port 55682:3: com.jcraft.jsch.JSchException: Auth cancel [preauth]
2020-04-03T17:29:10Z sshd[701694298]: Disconnected from authenticating user root 192.168.100.40 port 55682 [preauth]
Cntrl-Alt-F1
访问 shell。#pam_tally2 --user root #pam_tally2 --user root --reset #pam_tally2 --user root
有关更多信息,请参阅 VMware 文章 ESXi 密码和帐户锁定。
观看有关 ESXi 故障修复解锁 root 用户帐户的视频。
持续时间:00:04:56 (hh:mm:ss)
如果可用,可以使用此视频播放器上的设置或 CC 图标选择隐藏式字幕(字幕)语言设置。
相关资源
以下是一些与此主题相关的推荐资源,您可能会感兴趣: