Security Compliance
Change the account or password used for the Patch Manager service
This article describes how to change the account or password used for the EminentWare Data Grid Service (Patch Manager) service.
First published date
Last published date
Overview
Should you decide to modify the password or account utilized to start the EminentWare Data Grid Server service, follow the subsequent procedure to guarantee the service's startup post-change.
Product section
Resolution
If you are changing the account that starts the EminentWare Data Grid service, verify the following on the Patch Manager server (Automation servers as well if you have both Primary and Automation Servers).
- Open secpol.msc > Local Security Policy > Security Settings > Local Policies > User Rights Assignment > Log on as a service, the service account is listed in the Log on as a service Properties window
- Following settings are disabled in Security Settings > Local Policies > Security Options
- Windows Server 2003: Network access: Do not allow storage of credentials or.NET Passports for network authentication
- Windows Server 2008 and 2012: Network access: Do not allow storage of passwords and credentials for network authentication
- The service account has Full Control on the HKEY_LOCAL_MACHINE\SOFTWARE\EminentWare registry key.
- The service account is in the local Administrators group.
On the DB server
- Make sure the service account to be used has sysadmin rights to EminentWare database.
Steps (Server and DB part)
- Close the Patch Manager console.
- Open Windows Service Manager snap-in > Stop EminentWare Data Grid service.
- Clear MEKey and MPKey strings in the Registry:
- Open Registry Editor (regedit).
- Expand HKEY_LOCAL_MACHINE\SOFTWARE\EminentWare\Data Grid Service\Roles\Application\ and select Data Folder.
- Select MEKey and MPKey and delete. They will be recreated automatically.
- NOTE: be sure to DELETE the keys, don't just clear the value of the key.
- Open Computer Management > Local Users and Groups MMC snap-in on Patch Manager server
- Add the new user account to the Administrators group.
- Assign that new user a password - this part applies only if you are adding/updating the Local User account, if you are using domain/service account skip this). If just changing the existing EminentWare Data grid service user password, select the account in Local Users and change the existing password.
- We now need to link the new user account to the EminentWare Database via SQL Management Studio
- Login to the Database Server via SQL Management Studio
- Expand the security tab > Right click on security and select new login
- Assign that user SA (sysadmin) rights to the Eminentware database
- Change the password or add new user account you want to use to start the EminentWare Data Grid service on Patch manager server.
- Go back to Windows Service manager > Select EminentWare Data Grid service.
- Right-click and select Properties.
- Click on Log On tab.
- Make the necessary changes to the account and/or password, and then click OK.
- Start the EminentWare Data Grid service.
If you replaced Eminentware DataGrid Service User account, then you may run into "Certificate validation / missing permission" error on both Primary and Automation servers, follow the steps in Certificate error message displays when logging in to Patch Manager (site.com) to fix this.
Patch manager console part
- Open the Patch Manager console.
- Expand Patch Manager System Configuration and select Security and User Management.
- Click the Credentials tab.
- Update the Credentials for ALL the accounts.
- Right-click a credential on the Credentials tab and select Change Password.
- Enter and confirm the new password, and then click Save.
- Repeat step a and step b for the remaining credentials.
- If you set up email notifications, change the password stored for that task.
- Expand Patch Manager System Configuration > Patch Manager Servers > and select Application Servers.
- Select the application server.
- Click the Application Server Settings tab and select Email Configuration: SMTP Server logon user password in the Setting Name column.
- Click Modify Setting in the Application Servers pane.
- Enter the new password, and then click OK.
- If you set a password in Proxy Settings for Software Publishing, perform the following steps:
- Expand Administration and Reporting and select Software Publishing.
- Click Synchronization Settings in the Actions pane.
- Click the Proxy Settings tab and update the password.
- Click OK.
- If you set a proxy password for your Application Servers, perform the following steps:
- Expand Patch Manager System Configuration > Patch Manager Servers and select Application Servers.
- In the center pane, select the application server and click the Application Server Settings tab.
- Select the Password setting.
- Click the Action menu, and then select Modify Setting.
- Enter the new password, and then click OK.