• Not Answered

DeltaVAdmin default password in v12.3

We are currently testing an upgrade on one of our systems from v9 to v12. In all previous versions we have set the Delta V admin password to default, we realize this is not ideal but we have quite a lot of systems and found it easier to manage this way (it saves us having to change this password when someone leaves etc). In version 12 you cant now set this to default, what do other people do to manage this password or get around the problem of issuing this password to engineers working on the system in the short term and then leaving site ?

2 Replies

  • This is a good question, and I did not even realize 12.3 enforces a non-default password until I read this.

    We have clients that are implementing regular password changes of service accounts to minimize security vulnerabilities, something on the order of once per year, and are using enterprise password management software and site procedures to keep this process under control, not just for DeltaV but all manner of service accounts across different automation and business systems.

    The number of people who know the DeltaVAdmin password for a particular system should be kept to a minimum; after all you only really need it when adding or replacing workstation nodes, and most of those activities should be conducted during normal business hours (except maybe for a mission critical server failure and replacement).  This obviously becomes difficult if you are employing a managed services group for administration.

    I don't suggest making it the same for different systems at your site, either, unless the same group of adminstrators have responsibility on those various systems.

     

     

  • In reply to Youssef.El-Bahtimy:

    I agree with the theory it should be changed regularly, maybe once per year, the main issue we have is we use some contract personnel to assist us in the maintenance of the systems and one of the tasks these people carry out is swapping out of failed workstations which is really the only time you need the DeltaVAdmin password, we have procedures now that do not require us to give out the administrator password for the system and each person will have a named administrator account that can be removed when they leave. To change the DeltaVAdmin account you have to visit every workstation and we have some systems that are spread out over several locations that can be upto 3 miles apart so if for any reason we have a high turnover of people to keep the system secure it is much easier to have the default option on the DeltaVAdmin account.

    I was wondering if other people have had a similar issue and managed to come up with a workaround.

    Thankyou for your reply.