Skip to main content
Question

Dealing with forgotten dbamin password or deleted AUTHENTICATION records

  • July 12, 2019
  • 3 replies
  • 18 views

MaciejPaliwoda
Forum|alt.badge.img+2

Hello,
I have a case from Customer Security Team. Assume hypothetical situation when malicious user (with admin rights) will:
- change dbadmin password
or

  • delete all authenticaton records (including the ones related to a local trust or local password authentication)

How we can restore access to the DB for dbadmin (if we do not have other users with admin rights).
Fore version below 8 was a trick with changing the local config file, but it seems that this parameter is now part of Configuration Parameters
Thanks in advance....

M.

3 replies

mosheg
Forum|alt.badge.img+2
  • Participating Frequently
  • July 12, 2019

To reset dbadmin password you need either the current Vertica dbadmin password or the system root password.
One who has DB or System super user capabilities can delete data and harm the system in many ways.
To avoid the risk, it is possible to program or write a script that will require two user approvals preceding a sensitive action.


Car1os
Forum|alt.badge.img
  • Participating Frequently
  • July 12, 2019

You can use the catalog editor to change the dbadmin password. Support can guide the customer to do this.


skeswani
Forum|alt.badge.img
  • Participating Frequently
  • July 12, 2019

This is where backups are helpful, as you can restore from a backup to some extent. This is just another kind of disaster and having a DR plan should apply here