-
Notifications
You must be signed in to change notification settings - Fork 360
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Securing your Wazuh installation
API section is changing every password
#8025
Comments
Reopening this issue because the related article was not fixed. Proof https://documentation-dev.wazuh.com/v4.10.0-rc2/installation-guide/wazuh-dashboard/step-by-step.html Also, this should be considered to be backported to 4.x documentation |
Research 20/12After testing in a real environment, without the The following logs are from version 4.9:
|
Hi @jnasselle, it seems you got a different output than @JuanGarriuz. Was the Wazuh indexer deployed in the same host that the Wazuh server where you run the command to change the password for the Wazuh server API users? According to the documentation (https://documentation.wazuh.com/4.9/user-manual/user-administration/password-management.html) the According to the information provided by @JuanGarriuz, omitting the usage of We should investigate the logic to change the password and the usage of options. |
I confirm the test done by @JuanGarriuz. When I use this command I tried to test all the possibilities. |
PRs reviewing and merging blocked. Waiting for definitions about closing the PRs still open and reverting merged ones. |
During wazuh/wazuh#27183 it was found that https://documentation.wazuh.com/current/installation-guide/wazuh-dashboard/step-by-step.html#securing-your-wazuh-installation, in particular the Distributed Deployment tab, the following step is changing every password, while only should change API
This could be an issue if the Wazuh Manager co-exist with Wazuh Dashboard in the same host.
Current behavior when the Wazuh Master node and Wazuh Dashboard coexist on the same host
Expected behavior when the Wazuh Master node and Wazuh Dashboard coexist on the same host
Conclusion
This could be the result of
--change-all
parameter at Step 2, but a propper RCA should be doneThe text was updated successfully, but these errors were encountered: