Sec/User Mgmt: Step 2. Change the Default admin Passwords

Document created by RSA Information Design and Development on Jun 25, 2017Last modified by RSA Information Design and Development on Aug 28, 2017
Version 3Show Document
  • View in full screen mode
  

This topic provides instructions for changing the admin password for the Security Analytics service and for the Security Analytics Core services.

The system administrator's user account is installed with Security Analytics. The username is admin and the default password is netwitness. The Administrators role is assigned to admin. This role has full system privileges to control what a user can do and which services a user can access. The only modification you can make to this account is to change the password. Unlike other Security Analytics users, changes to the admin user password do not automatically propagate to downstream services. When you configure the password strength settings, they apply to all Security Analytics users, including the admin user.

Passwords, an important aspect of computer security, are the front line of protection for your system. The admin user is pre-installed in Security Analytics and on each Security Analytics Core service. For security, you create the Users and Roles for your organization in Security Analytics, and on each Security Analytics Core service.

Best Practices

RSA recommends the following best practices:

  • Change the admin password of each service from the default.
  • Create a different password for the admin account on each service.

Change the admin Password for the Security Analytics Service

Change the admin password for the Security Analytics service in the Profile view. See Change Password in the Security Analytics Getting Started Guide. The password of the admin user does not propagate to Core services.

Note: After you change the admin password, you must remove and re-add a Data Source on the Reporting Engine. For more information, see the Remove and re-add a Data Source on the Reporting Engine section below.

Change the admin Password for Security Analytics Core Services

To change the admin password for a Core service:

  1. In the Security Analytics menu, select Administration > Services.
  2. Select a service, and then select  > View > Security.
  3. On the Users tab, select the admin user.

    ChgAdmSrvPwd.png

  4. In the Password field, type a new admin password for the selected service.
  5. In the Confirm Password field, retype the new password.
  6. Click Apply.

Note: After you change the admin password, you must remove and re-add a Data Source on the Reporting Engine. For more information, see Remove and re-add a Data Source on the Reporting Engine below.

Remove and re-add a Data Source on the Reporting Engine

Reporting Engine validates a Data Source using the Data Source username and password. If you change the username or password of a Data Source, you must remove and re-add the Data Source.

To remove and re-add a data source on the Reporting Engine:

  1. In the Security Analytics menu, select Administration > Services.
  2. In the Services view, select Reporting Engine and  View > Config.
  3. Click the Sources tab.
  4. Select a service to remove and click
  5. Click  and select Available Services.
  6. Select the service you removed in step 4 and click OK.
  7. When prompted, enter the new username and password for the service.

Change the admin Password for a Service Using the REST API

In rare circumstances, you may need to change the admin password for a Core service outside of the Security Analytics user interface. This is simply another way to perform the Security Analytics Core password change, and is not the preferred method.

To change the admin password for the service using the REST User Interface:

  1. Open a web browser, and go to the following URL:

    <hostname>:<port>

    where the hostname is the name of a Security Analytics Core service and port is the port used for REST communication. Here is an example for a Security Analytics Decoder: http://10.20.30.40:50104

    The authentication dialog is displayed.

  2. In the dialog enter the user name and password used for authentication as admin on the service, and click OK. The default user name is admin and the default password is netwitness.

    The REST window for the service is displayed.

  3. Navigate through the node structure to users/accounts/admin/config.

    The user configuration fields for admin are displayed in the browser window.

  4. In the Password field, type a new admin password and click Set.
You are here
Table of Contents > Set Up System Security > Step 2. Change the Default admin Passwords

Attachments

    Outcomes