Create a new password for the Cortex XSOAR administrator account, if you are unable to log in, by manually adding a new administrator.
If the administrator cannot log in and does not know the password, you need to add a new administrator. You can then change the password for the current administrator.
To add a new administrator, you need to create a one-time configuration (OTC) file, in which you define the user configurations. After the file is saved, restart the Cortex XSOAR server. The OTC file is automatically deleted.
Create a new administrator.
As the root user, create a
/var/lib/demisto/otc.conf.json
file with content similar to the following by using thetouch
(create) andvim
(edit) commands.{ "users": [ { "username": "newadmin", "password": "veryStrongPassword!", "email": "admin@example.com", "phone": "+650-123456", "name": "New Admin Dude", "defaultAdmin": true, "roles": { "demisto": [ "Administrator" ] } } ] }
If you do not want the new administrator to be the default administrator, remove
defaultAdmin
or change it tofalse
.Save the file.
Ensure the file has
demisto:demisto
ownership by typing the following command:chown demisto:demisto /var/lib/demisto/otc.conf.json
Restart the Cortex XSOAR server by running the following command:
systemctl restart demisto
The file is removed when Cortex XSOAR restarts.
Log in to Cortex XSOAR by using the new administrator credentials created in step 1.
In this example, the username is
newadmin
and the password isveryStrongPassword!
.Change the current administrator’s password.
Go to Reset P/W.
→ → , select the current administrator checkbox and clickChange the new password as required, and click Save.
Log out of Cortex XSOAR.
(Optional) Remove the new administrator you created in step 1.
Login to Cortex XSOAR using the current administrator credentials, including the new password.
Go to Remove.
→ → , select the new administrator checkbox and clickIf the new administrator is also a default administrator you can remove the user by selecting the user, clicking Roles, and unchecking the Set as Default Admin checkbox.