Password management method, computer equipment, readable storage medium and program product
By installing a virtual machine on the operating system and setting the same network environment, and obtaining and modifying the board management controller password, the problem of long time for BMC password modification is solved, and the efficiency and reliability of large-scale server delivery is improved.
Patent Information
- Application Number
- CN202510885244.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2045-06-30
AI Technical Summary
In the prior art, the password modification time of the substrate management controller (BMC) is long, making it difficult to deal with server delivery scenarios of different operating systems corresponding to large batches of different models, affecting delivery time.
By judging the operating system type, installing the target type of virtual machine, setting the execution server and the server to be managed, obtaining the BMC Internet protocol address and password, and using the substrate management controller configuration file to modify the batch password.
It realizes the efficiency and reliability of the board management controller password management under different operating systems, supports batch password modification of different server models, and shortens delivery time.
Smart Images

Figure CN120387159A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a password management method, a computer device, a readable storage medium, and a program product. Background Art
[0002] During the delivery process of a server, according to the initialization requirements of a customer, the server needs to be initialized, and it is an essential requirement to modify the password of the Baseboard Management Controller (BMC) of the server to a high-strength password.
[0003] In response to the initialization requirements proposed by the customer, when performing large-scale server configuration, single-unit operation will seriously lengthen the delivery time, and the implementation environment will also be greatly restricted, thereby resulting in a longer delivery time and affecting the delivery efficiency. In related technologies, a batch tool is used to batch modify the BMC password for the same model. However, this method is limited by the model restrictions of the servers to be operated. Generally, only servers of the same model can be configured in one batch, resulting in a long time for modifying the password of the baseboard management controller and making it difficult to handle the delivery scenarios of a large number of servers with different operating systems corresponding to different models. Summary of the Invention
[0004] This application provides a password management method, a computer device, a readable storage medium, and a program product to solve the technical problem of the long time for modifying the password of the baseboard management controller in related technologies.
[0005] This application provides a password management method, including: determining whether the operating system type is a target type, and in response to the operating system type not being the target type, installing a virtual machine of the target type on the operating system; setting an execution server connected to the in-band network and multiple servers to be managed connected to the out-of-band network to be in the same network segment; obtaining the Internet Protocol addresses corresponding to the baseboard management controllers of the multiple servers to be managed and modifying the passwords of the baseboard management controllers; filling the Internet Protocol addresses and the modified passwords of the baseboard management controllers in a baseboard management controller configuration file, and copying the baseboard management controller configuration file to the non-target type operating system after installing the virtual machine of the target type; in response to the network status between the execution server and the multiple servers to be managed being in a connected state and the firewall status of the multiple servers to be managed being in a connected state, modifying the passwords of the baseboard management controllers corresponding to the baseboard management controllers of the multiple servers to be managed based on the baseboard management controller configuration file.
[0006] This application also provides a computer device, including: a memory for storing a computer program; a processor for implementing the steps of the password management method in the following embodiments when executing the computer program.
[0007] Determine whether the operating system type is the target type. In response to the operating system type being a non-target type, install a virtual machine of the target type on the operating system; set the execution server connected to the in-band network and multiple managed servers connected to the out-of-band network to be in the same network segment; obtain the Internet protocol addresses corresponding to the baseboard management controllers of the multiple managed servers and modify the baseboard management controller passwords; fill in the Internet protocol addresses and the modified baseboard management controller passwords in the baseboard management controller configuration file, and copy the baseboard management controller configuration file to the non-target type operating system after installing the virtual machine of the target type; in response to the network status between the execution server and the multiple managed servers being in a connected state and the firewall status of the multiple managed servers being in a connected state, modify the baseboard management controller passwords corresponding to the baseboard management controllers of the multiple managed servers based on the baseboard management controller configuration file.
[0008] The present application also provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of the password management method in the following embodiments are implemented.
[0009] Determine whether the operating system type is the target type. In response to the operating system type being a non-target type, install a virtual machine of the target type on the operating system; set the execution server connected to the in-band network and multiple managed servers connected to the out-of-band network to be in the same network segment; obtain the Internet protocol addresses corresponding to the baseboard management controllers of the multiple managed servers and modify the baseboard management controller passwords; fill in the Internet protocol addresses and the modified baseboard management controller passwords in the baseboard management controller configuration file, and copy the baseboard management controller configuration file to the non-target type operating system after installing the virtual machine of the target type; in response to the network status between the execution server and the multiple managed servers being in a connected state and the firewall status of the multiple managed servers being in a connected state, modify the baseboard management controller passwords corresponding to the baseboard management controllers of the multiple managed servers based on the baseboard management controller configuration file.
[0010] The present application also provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of the password management method in the following embodiments are implemented.
[0011] Determine whether the operating system type is the target type. In response to the operating system type being a non-target type, install a virtual machine of the target type on the operating system; set the execution server connected to the in-band network and multiple managed servers connected to the out-of-band network to be in the same network segment; obtain the Internet protocol addresses corresponding to the baseboard management controllers of the multiple managed servers and modify the passwords of the baseboard management controllers; fill in the Internet protocol addresses and the modified passwords of the baseboard management controllers in the baseboard management controller configuration file, and copy the baseboard management controller configuration file to the non-target type operating system after installing the virtual machine of the target type; in response to the network status between the execution server and the multiple managed servers being a connected state and the firewall status of the multiple managed servers being a connected state, modify the baseboard management controller passwords corresponding to the baseboard management controllers of the multiple managed servers based on the baseboard management controller configuration file.
[0012] For the password management method provided in this application, since it determines whether the operating system type is the target type, and in response to the operating system type being a non-target type, installs a virtual machine of the target type on the operating system; sets the execution server connected to the in-band network and multiple managed servers connected to the out-of-band network to be in the same network segment; obtains the Internet protocol addresses corresponding to the baseboard management controllers of the multiple managed servers and modifies the passwords of the baseboard management controllers; fills in the Internet protocol addresses and the modified passwords of the baseboard management controllers in the baseboard management controller configuration file, and copies the baseboard management controller configuration file to the non-target type operating system after installing the virtual machine of the target type; in response to the network status between the execution server and the multiple managed servers being a connected state and the firewall status of the multiple managed servers being a connected state, modifies the baseboard management controller passwords corresponding to the baseboard management controllers of the multiple managed servers based on the baseboard management controller configuration file. Therefore, it supports password modification for baseboard management controllers under different operating systems corresponding to different server models, and when the network status between the execution server and the multiple managed servers and the firewall status of the multiple managed servers are both in a connected state, performs the baseboard management controller password modification operation, which can improve the efficiency and reliability of baseboard management controller password management. Description of the Drawings
[0013] To more clearly illustrate the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0014] Figure 1 It is a flowchart of the password management method provided by an embodiment of the present application; Figure 2Schematic flowchart of a password management method provided by another embodiment of the present application; Figure 3 Schematic structural diagram of a password management device provided by an embodiment of the present application; Figure 4 Internal structure diagram of a computer device provided by an embodiment of the present application. Detailed implementation manners
[0015] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0016] It should be noted that in the description of the present application, the terms "including", "comprising" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects and are not used to describe a specific order or sequence.
[0017] Currently, servers have been widely used in all walks of life, covering multiple industries such as finance, communication, and transportation.
[0018] The BMC is a hardware management chip independent of the operating system, providing out-of-band management functions. It allows remote operation even when the server is powered off or the operating system crashes. Its core functions include: hardware monitoring and management, remote control, fault diagnosis and recovery, security auditing, etc.; the BMC has underlying control over the server, and its password is the core of security protection. The functions of the BMC user password mainly include: preventing unauthorized access (high-risk privilege: if an attacker obtains the BMC password, they can remotely control the server power supply, modify the firmware, steal data or implant malware. Hidden attack surface: the BMC is usually exposed through an independent network interface, and a weak password may become a springboard for intruding into the internal network), ensuring business continuity (risk of malicious operations: password leakage may cause the server to be illegally powered off, configuration tampering or firmware damage, resulting in service interruption. Physical security supplement: even if the physical protection of the computer room is strict, BMC password leakage may still allow attackers to remotely carry out sabotage), compliance requirements (most security standards (such as PCI DSS, ISO 27001) require strict management of access rights to the out-of-band management interface, and a strong password is a basic requirement), and defending supply chain attacks (avoid using default passwords (such as admin / admin) to prevent automated attack tools using factory credentials from invading). The BMC is the "last line of defense" for server hardware management. Its interface provides powerful out-of-band management capabilities, but password leakage may lead to catastrophic consequences. By implementing a strong password policy, network isolation, and continuous monitoring, security risks can be significantly reduced to ensure the stable operation of the server.
[0019] During the delivery process, it is an essential requirement to modify the server BMC user to a high-strength password according to the customer's initialization requirements. In response to the initialization requirements put forward by the customer, when performing large-scale server configurations, single-unit operations will seriously extend the delivery time, and the implementation environment will also be greatly restricted, thereby leading to a longer delivery time and affecting the delivery efficiency.
[0020] In Related Technology One, the password of the corresponding BMC user is mainly modified through the BMC web interface. However, this method can only be operated on a single unit. For a large number of sites where the BMC password needs to be modified, it cannot be completed quickly, seriously extending the delivery cycle; and this method requires each server to log in to the BMC web management interface, and some confidential customers may not be able to provide the corresponding information, thus preventing configuration.
[0021] In Related Technology Two, a batch tool is used to batch execute the modification of the password of the corresponding BMC user. However, the environment for implementing this method has limitations. It can complete the batch modification of the BMC password, but this method is limited by the models to be operated. Generally, only servers of the same model can be configured in one batch, and it is not possible to operate on a mixed scenario in the same batch.
[0022] It can be seen that for the password configuration of BMC users, the existing configuration methods are as follows: for single - machine configuration, it can be done in the BMC web interface. Modify each machine individually through the user function (this method takes a long time and will extend the delivery time for large - batch deliveries, and cannot efficiently meet customer requirements); there is also a corresponding batch tool currently to modify the BMC passwords of the same model in batches, but this method is limited by the models to be operated. Generally, only servers of the same model can be configured in one batch, and it is not possible to operate in the same batch for a mixed scenario.
[0023] In response to the above - mentioned technical problems, as Figure 1 shown, an embodiment of the present application provides a password management method, which specifically includes the following steps: Step 101: Determine whether the operating system type is the target type. In response to the operating system type being non - target type, install a virtual machine of the target type on the operating system.
[0024] Specifically, obtain the operating system type and determine whether the operating system type is the target - type operating system; the target - type operating system is an operating system that supports shell scripts; in response to the operating system type being a non - target - type operating system, install a virtual machine of the target type on the operating system.
[0025] Specifically, the running script in the present application is a shell script, and subsequently, the password modification operation of the baseboard management controller of any server can be automatically executed according to the running script. Here, first obtain the operating system type and determine whether the operating system type is an operating system type that supports shell scripts. When the operating system type is non - target type, it is considered that the current operating system does not support shell scripts, and a virtual machine of the target type needs to be installed on the current operating system to make the operating system support shell scripts. The virtual machine of the target type here can be a Linux virtual machine. A Linux virtual machine is a special software that runs on the host operating system and can simulate a complete computer hardware system environment.
[0026] Currently, the mainstream operating systems are Windows operating system and Linux operating system. When the operating system is a Linux operating system environment, the running script can run under the current mainstream Linux distribution operating systems such as CentOS, Redhat, and Ubuntu. If the operating system is a Windows system environment, installing a Linux virtual machine can also execute shell scripts. In this way, the execution server and multiple servers to be managed have scalability under the Windows or Linux system environment.
[0027] In this way, it is not necessary to use the customer environment. The operator only needs to install a virtual machine on his own environment and build a Linux system environment to perform batch operations. If the customer provides an operating environment, this invention also covers mainstream system environments based on the Linux system, including CentOS, Redhat, and Kylin, etc., covering the delivery site to the greatest extent.
[0028] Step 102: Set the execution server connected to the in-band network and multiple servers to be managed connected to the out-of-band network to be in the same network segment.
[0029] Specifically, before setting the execution server to connect to the in-band network and setting multiple servers to be managed to connect to the out-of-band network, it further includes: determining whether the Internet protocol addresses corresponding to the baseboard management controllers of the multiple servers to be managed are allocated; in response to the Internet protocol addresses corresponding to the baseboard management controllers of the multiple servers to be managed not being allocated, installing the Dynamic Host Configuration Protocol on the execution server, and allocating the Internet protocol addresses corresponding to the baseboard management controllers for the multiple servers to be managed based on the Dynamic Host Configuration Protocol.
[0030] First, it is necessary to determine whether there is a network environment for the server to be managed (that is, whether the server to be managed installs the Dynamic Host Configuration Protocol). If the server to be managed has no network environment, it is necessary to build a network environment with the server executing the command as a DHCP host (Dynamic Host Configuration Protocol) so that the server to be managed can automatically obtain its corresponding baseboard management controller Internet protocol address. If the server to be managed has a network environment, directly connect the execution server to the in-band network and connect the server to be managed to the out-of-band network. The Dynamic Host Configuration Protocol is a network protocol for a local area network. It means that a server controls a range of IP addresses, and when a client logs in to the server, it can automatically obtain the IP address and subnet mask assigned by the server.
[0031] Further, determine whether the multiple servers to be managed connected to the out-of-band network and the execution server connected to the in-band network are in the same network segment; in response to the multiple servers to be managed connected to the out-of-band network and the execution server connected to the in-band network not being in the same network segment, load a network connection tool on the execution server to establish network communication between the execution server and the multiple servers to be managed through the network connection tool, so that the multiple servers to be managed connected to the out-of-band network and the execution server connected to the in-band network are in the same network segment.
[0032] Step 103: Obtain the Internet protocol addresses corresponding to the baseboard management controllers of the multiple servers to be managed and modify the baseboard management controller password; fill in the Internet protocol addresses and the modified baseboard management controller password in the baseboard management controller configuration file, and copy the baseboard management controller configuration file to the non-target type operating system after installing the virtual machine of the target type.
[0033] Specifically, obtain the Internet Protocol (IP) address, user name, initial Baseboard Management Controller (BMC) password, and modified BMC password corresponding to the BMCs of multiple servers to be managed; sequentially select any one of the multiple servers to be managed as the target server to be managed; write the IP address, user name, initial BMC password, and modified BMC password corresponding to the BMC of the target server to be managed into any line in the BMC configuration file.
[0034] Exemplarily, each server information to be managed can be written into each line of the BMC configuration file in the execution server in the format of IP address, user name, initial BMC password, and modified BMC password corresponding to the BMC, and the information of multiple servers to be managed is displayed line by line. Refer to the following: cat< <eof>bmc_list.csv 192.168.1.101,admin,Old Password 1,New Password 1 192.168.1.102,root,Old Password 2,New Password 2 192.168.1.103,Administrator,Old Password 3,New Password 3 EOF It can be seen that the first column in the Baseboard Management Controller (BMC) configuration file is the Internet Protocol address (BMC IP) corresponding to the BMC, the second column is the user name of the BMC, the third column is the old password (initial BMC password), and the fourth column is the new password (modified BMC password). Each server occupies one line, and the data is separated by commas (English). Ensure that the information is filled in correctly. A specific example is IP: 10.49.32.45, user name: joker5, current password (old password): jszx2024Niu!, new password: Inspur5%.
[0035] Further obtain the BMC configuration file and the script file, copy the BMC configuration file and the script file to the non-target type operating system after the virtual machine of the installation target type, and change the read permission of the BMC configuration file and the script file to executable permission.
[0036] In this application, the execution server can build a shell script. A shell script is a script language based on shell commands used to automate the execution of a series of commands. The shell script can include the config.sh command (running script command) and bmc_list.txt (BMC configuration file). Specifically, after the execution server installs the script software, it can copy all the attachment files (the attachment files include the config.sh command (running script command) and bmc_list.txt (BMC configuration file)) to the current operating system and give them executable permission. In this way, the running script can be made executable on multiple operating systems.
[0037] Step 104: In response to the network status between the execution server and multiple servers to be managed being in a connected state and the firewall status of the multiple servers to be managed being in a connected state, modify the BMC password corresponding to the BMC of the multiple servers to be managed based on the BMC configuration file.
[0038] Specifically, obtain the network status of the execution server and multiple servers to be managed; use a network diagnostic tool to determine whether the network between the execution server and the multiple servers to be managed is connected; in response to the network status between the execution server and the multiple servers to be managed being in a connected state, run the Intelligent Platform Management Interface (IPMI) command to obtain the server sensor data of the multiple servers to be managed; in response to obtaining the server sensor commands of the multiple servers to be managed through the IPMI command, determine that the firewall status of the multiple servers to be managed is in a connected state.
[0039] This application also needs to ensure the network connectivity between the execution server and each server to be managed. To this end, based on the Baseboard Management Controller (BMC) configuration file, run the IPMI command to obtain the connection status of the transmission protocol ports of each server to be managed (the firewall status of multiple servers to be managed); run the ping command (a network diagnostic tool) to obtain the data transmission status of each server to be managed. It should be noted that the IPMI tool command and the ping command are stored in the running script. The ping command sends an ICMP (Internet Control Messages Protocol) echo request message to the destination and reports whether the desired ICMP echo (ICMP echo reply) is received. It is a command used to check whether the network is unobstructed or the network connection speed.
[0040] In a specific embodiment, to check the network connectivity between the execution server (operation host) and multiple servers to be managed, the following two steps are used for confirmation: 1. Confirm the network connectivity (the data transmission status of each server to be managed) through the ping command; 2. Confirm that the UDP port 623 of the server is open (firewall policy) through the IPMI instruction. Specifically, the port can be confirmed to be open through the command return value. At the same time, ensure that the BMC user modifying the password has administrator privileges. Non-administrator privileges cannot obtain the corresponding server information, and the currently configured BMC user in the configuration script also needs to have administrator privileges, otherwise, the operation of obtaining server information will fail when executed.
[0041] Specifically, obtain the script file from the operating system; obtain the user name. In response to setting the administrator privileges for the user name, run the script file to automatically modify the initial BMC password corresponding to the BMC of multiple servers to be managed to the modified BMC password corresponding to the BMC of multiple servers to be managed.
[0042] Among them, the running script file includes: executing the script file in the current directory through a target-type script interpreter; in response to the running of the script file, obtaining the output statements during the running of the script in real time, and displaying the output statements on the execution page of the execution server; in response to the completion of the execution of the script file, exporting the script execution log, and naming the exported script execution log with the script file execution directory and the time of exporting the script execution log.
[0043] In this application, the user name of the baseboard management controller is set with administrator privileges. Only when the user name has administrator privileges can important information recording the system configuration be obtained, the script file be run, and the passwords of the baseboard management controllers of multiple servers to be managed can be batch-modified through the script file.
[0044] When running the script file in this application, the output statements during the running of the script can also be recorded in real time and displayed on the execution interface of the execution server. After the execution of the script file is completed, the script execution log can be set to be exported. The script execution logs of each server will be recorded in the exported file. In the log file, the running logs corresponding to each server will be exported according to the information of the corresponding IP, and the reasons for the failure of the failed operations can be quickly located.
[0045] Execute the following command in the current directory: "config.sh". The execution log will be displayed on the execution page, and after the execution is completed, the execution log will be automatically exported to the directory where the current script is located, with the suffix named by the time.
[0046] In an embodiment, this application sets to obtain the unique identification code of the baseboard management controller chip of multiple servers to be managed and the initial baseboard management controller password; divide the initial baseboard management controller password to obtain multiple sub-initial baseboard management controller passwords; perform byte flipping on the multiple sub-initial baseboard management controller passwords so that the front bytes and the back bytes of the multiple sub-initial baseboard management controller passwords are swapped in position to generate multiple flipped passwords; perform exclusive OR operations on the bytes in the multiple flipped passwords to obtain multiple passwords to be concatenated; concatenate the multiple passwords to be concatenated and the unique identification code to obtain the modified baseboard management controller password.
[0047] Specifically, the initial Baseboard Management Controller (BMC) password can be divided into multiple sub-initial BMC passwords. Byte flipping is performed on each sub-initial BMC password among the multiple sub-initial BMC passwords to swap the positions of the front bytes and the back bytes of each sub-initial BMC password, generating multiple flipped passwords. Exclusive OR (XOR) operations are performed on each byte in each flipped password to obtain multiple passwords to be concatenated. The multiple passwords to be concatenated are concatenated with the unique identification code to obtain the modified BMC password. In this way, the diversity of formulating the modified BMC password is enriched. At the same time, when specifying the modified BMC password, the unique identification code is retained, improving the complexity of the modified BMC password while retaining the characteristics of the BMC.
[0048] In one embodiment, after modifying the BMC passwords corresponding to the BMCs of multiple servers to be managed based on the BMC configuration file, the following steps are further included: sequentially selecting any one of the multiple servers to be managed as the verification server; logging in to the verification server through the user management command and the modified BMC password corresponding to the verification server; in response to the failure of logging in to the verification server through the user management command and the modified BMC password corresponding to the verification server, determining that the modification of the BMC password corresponding to the verification server is unsuccessful.
[0049] This application also sets up a verification mechanism. After the BMC password modification operation is completed, the new password will be automatically used, that is, logging in with the modified BMC password. If the login fails, it will prompt the execution failure in the log, and the specific server to be managed can be confirmed according to the BMC Internet Protocol address (BMC IP), realizing fast fault location.
[0050] After determining that the password modification of the baseboard management controller corresponding to the verification server is unsuccessful, it is possible to determine whether the password length and password characters corresponding to the modified baseboard management controller password meet the requirements; in response to the password length and password characters not meeting the requirements, generate a first warning message, where the first warning message indicates that the password length and password characters of the verification server do not meet the requirements; in response to the password length and password characters meeting the requirements, determine whether the user name corresponding to the verification server has administrative privileges set; in response to the user name corresponding to the verification server not having administrative privileges set, generate a second warning message, where the second warning message indicates that the user name corresponding to the verification server does not have administrative privileges set; in response to the user name corresponding to the verification server having administrative privileges set, determine whether the firewall status of the verification server is in a connected state; in response to the firewall status of the verification server being in a non-connected state, generate a third warning message, where the third warning message indicates that the firewall status of the verification server is in a non-connected state.
[0051] After determining that the password modification of the baseboard management controller corresponding to the verification server is unsuccessful, it is possible to sequentially determine the length of the password corresponding to the modified baseboard management controller password and whether there are any illegal characters among the characters that make up the password. For example, whether the password length is 12 characters, and the illegal characters can include the space bar. The illegal characters and password length here can be set by the operator. If the verification password is incorrect, an alarm is immediately issued. After the verification password is correct, the next verification is carried out, including determining whether the user name has administrative privileges set and whether the firewall of the server is in a connected state, etc., until the reason for the unsuccessful password modification of the baseboard management controller is identified, and a corresponding warning message is generated based on this reason, so that the user can clearly view the reason for the unsuccessful password modification of the baseboard management controller.
[0052] In one embodiment, modifying the Baseboard Management Controller (BMC) password includes modifying the valid duration identifier, which consists of the generation time of the modified BMC password and the valid expiration time of the modified BMC password. Modifying the BMC passwords corresponding to the BMCs of multiple servers to be managed based on the BMC configuration file further includes: obtaining the valid duration identifiers for modifying the BMC passwords corresponding to the multiple servers to be managed; obtaining the target modification time for performing the password modification operation on the BMC passwords of the multiple servers to be managed, and sequentially selecting any one of the multiple servers to be managed as the verification server to be managed; determining whether the target modification time of the verification server to be managed matches the valid duration identifier of the verification server to be managed; in response to the valid duration identifier corresponding to the verification server to be managed matching the target modification time, adding the verification server to the cache queue and performing the password modification operation on the BMC passwords of the servers in the cache queue; in response to the valid duration identifier corresponding to the verification server to be managed not matching the target modification time, adding the verification server to the allocation queue and reallocating the modified BMC password for the servers in the allocation queue. In this way, through differential processing based on whether the target modification time of the verification server to be managed matches the valid duration identifier of the verification server to be managed, the verification server to be managed in the matching case is added to the cache queue, and the verification server to be managed in the non-matching case is added to the allocation queue, which can ensure that the password modification strictly complies with the security policy requirements.
[0053] In this application, a valid duration identifier is also set for modifying the BMC password. The valid duration identifier here is used to calibrate the valid duration of modifying the BMC password. If the execution time of any BMC password modification operation corresponding to the BMC password matches the valid duration identifier corresponding to this password, that is, the execution time of the BMC password modification operation corresponding to the BMC password is within the time range of the valid duration identifier corresponding to this password, it means that when the modification operation is executed, the modified BMC password has not expired. The unexpired modified BMC password is added to the cache queue, and the password modification operation is performed on the BMC passwords of the servers in the cache queue. When the execution time of the BMC password modification operation corresponding to the BMC password is not within the time range of the valid duration identifier corresponding to this password, it is considered that the modified BMC password has expired. The server corresponding to the modified BMC password is added to the allocation queue, and the modified BMC password is reallocated for the servers in the allocation queue. In this way, through time-driven password management, while ensuring security, the operation and maintenance complexity is significantly reduced, which is especially suitable for the ultra-large-scale data center scenario.
[0054] In this application, by using the shell language to develop and run scripts, with the help of the intelligent platform management interface tool system tool, it can cover the configuration environment of most operating systems. The intelligent platform management interface tool has high compatibility and reliability with existing BMCs and meets the conditions for batch execution; at the same time, by using the intelligent platform management interface tool, on-site batch operations of mixed multiple models can be performed. For on-site environments with multiple models, this script can be executed once to complete the password modification of the corresponding BMC user; and the operation log during configuration is retained and the operation results are verified to facilitate tracing of the execution results.
[0055] In one embodiment, since the Intelligent Platform Management Interface Tool (IPMITOOL) has a Windows version, it can be run in a Windows environment through batch processing. Specifically, the BMC configuration files for multiple servers to be managed are obtained, and the Intelligent Platform Management Interface Tool is invoked through batch processing. The BMC password modification information, including the modification validity period, is stored. To modify multiple user passwords on a single server, the corresponding parameters are simply added to the BMC configuration file. This enables complete BMC management capabilities in a Windows environment, reducing enterprise operation and maintenance costs. Furthermore, a single execution can batch-process password modification operations for multiple BMCs, improving BMC password modification efficiency.
[0056] See also Figure 2 In order to better describe the password management method provided by this application, a specific example is given for illustration: S1: Build an operating environment (Linux operating environment, specifically an operating environment of a Linux distribution such as CentOS, Redhat, or Ubuntu).
[0057] Determine whether the operating system type supports shell scripts. If the operating system type is the target type, the current operating system is considered to support shell scripts. A virtual machine of the target type needs to be installed on the current operating system to enable the operating system to support shell scripts. The target virtual machine can be a Linux virtual machine. See step 101 for details.
[0058] S2: Connect multiple managed servers and the operation end host (execution server) to the same network environment; the execution server is connected to the in-band network, and the managed servers are connected to the out-of-band network.
[0059] The execution server connected to the in-band network and the multiple servers to be managed connected to the out-of-band network are set to be in the same network segment, see the description of step 102 for details.
[0060] S3: Power on the server to be managed and ensure that the BMC starts up and its IP address can be obtained. Write the corresponding BMC IP information of the service to be configured into the "bmc_list.txt" file as required.
[0061] Obtain the Internet protocol addresses corresponding to the baseboard management controllers of multiple servers to be managed and modify the passwords of the baseboard management controllers; fill in the Internet protocol addresses and the modified passwords of the baseboard management controllers in the baseboard management controller configuration file, and copy the baseboard management controller configuration file to the non-target type operating system after installing the virtual machine of the target type. For details, see the description in step 103.
[0062] S4: Execute the ping and Intelligent Platform Management Interface (IPMI) tool commands on the execution server to confirm the return values (confirm the network status between the execution server and multiple servers to be managed and the firewall status of multiple servers to be managed).
[0063] Determine the network status between the execution server and multiple servers to be managed and the firewall status of multiple servers to be managed according to the return values of the IPMI tool commands. When the return values indicate that the network status between the execution server and multiple servers to be managed and / or the firewall status of multiple servers to be managed is not connected, re-check the network status between the unconnected execution server and multiple servers to be managed and / or the firewall status of multiple servers to be managed, and re-configure.
[0064] S5: Execute the batch script config.sh (run the script to modify the passwords of the baseboard management controllers corresponding to multiple servers to be managed based on the baseboard management controller configuration file) In response to the network status between the execution server and multiple servers to be managed being connected and the firewall status of multiple servers to be managed being connected, modify the passwords of the baseboard management controllers corresponding to multiple servers to be managed based on the baseboard management controller configuration file. For details, see the description in step 104.
[0065] S6: Determine whether the modification of the baseboard management controller password is successful.
[0066] Specifically, it can include that after the operation of modifying the baseboard management controller password is completed, the new password will be automatically used, that is, log in with the modified baseboard management controller password. If the login fails, it will prompt the execution failure in the log. When the password modification is not successful, the script execution log can be obtained, problems can be troubleshot according to the script execution log, the script file can be re-run, and the password modification operation of the baseboard management controller of any server can be automatically executed according to the running script.
[0067] An embodiment of the present application provides a password management device. Specifically, the password management device is as follows Figure 3 As shown, the password management device includes: a judgment module 20, a setting module 21, a writing module 22, and a modification module 23.
[0068] The judgment module 20 is used to judge whether the operating system type is the target type. In response to the operating system type not being the target type, install a virtual machine of the target type on the operating system.
[0069] The setting module 21 is used to set the execution server connected to the in-band network and multiple to-be-managed servers connected to the out-of-band network to be in the same network segment.
[0070] The writing module 22 is used to obtain the Internet protocol addresses corresponding to the baseboard management controllers of multiple to-be-managed servers and modify the baseboard management controller passwords; fill in the Internet protocol addresses and the modified baseboard management controller passwords in the baseboard management controller configuration file, and copy the baseboard management controller configuration file to the non-target type operating system after installing the virtual machine of the target type.
[0071] The modification module 23 is used to, in response to the network status between the execution server and multiple to-be-managed servers being in a connected state and the firewall status of multiple to-be-managed servers being in a connected state, modify the baseboard management controller passwords corresponding to the baseboard management controllers of multiple to-be-managed servers based on the baseboard management controller configuration file.
[0072] As Figure 4 shown, an embodiment of the present application also provides a computer device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any of the above-mentioned password management method embodiments.
[0073] An embodiment of the present application also provides a computer-readable storage medium. A computer program is stored in the computer-readable storage medium. Among them, the computer program is configured to execute the steps in any of the above-mentioned password management method embodiments when running.
[0074] In an exemplary embodiment, the above-mentioned computer-readable storage medium may include, but is not limited to: various media such as USB flash drives, read-only memories (ROM for short), random access memories (RAM for short), mobile hard disks, magnetic disks, or optical discs that can store computer programs.
[0075] Those skilled in the art may further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be determined to exceed the scope of this application.
[0076] The above has introduced in detail a password management method provided by this application. Specific examples are used herein to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of this application, several improvements and modifications can still be made to this application, and these improvements and modifications also fall within the protection scope of this application.< / eof>
Claims
1. A password management method, characterized in that, The described password management method includes: Determine whether the operating system type is the target type. In response to the operating system type not being the target type, install a virtual machine of the target type on the operating system; Set the execution server connected to the in-band network and the multiple servers to be managed connected to the out-of-band network to be in the same network segment; Obtain the Internet protocol addresses corresponding to the baseboard management controllers of the multiple servers to be managed and modify the passwords of the baseboard management controllers; fill in the Internet protocol addresses and the modified baseboard management controller passwords in the baseboard management controller configuration file, and copy the baseboard management controller configuration file to the non-target type operating system after installing the virtual machine of the target type; In response to the network status between the execution server and the multiple servers to be managed being in a connected state and the firewall status of the multiple servers to be managed being in a connected state, modify the baseboard management controller passwords corresponding to the baseboard management controllers of the multiple servers to be managed based on the baseboard management controller configuration file.
2. The password management method according to claim 1, wherein The step of determining whether the operating system type is the target type. In response to the operating system type not being the target type, installing a virtual machine of the target type on the operating system includes: Obtain the operating system type and determine whether the operating system type is the target type operating system; the target type operating system is an operating system that supports shell scripts; In response to the operating system type not being the target type operating system, install a virtual machine of the target type on the operating system.
3. The password management method according to claim 1, wherein The step of setting the execution server connected to the in-band network and the multiple servers to be managed connected to the out-of-band network to be in the same network segment includes: Set the execution server to be connected to the in-band network and set the multiple servers to be managed to be connected to the out-of-band network; Determine whether the out-of-band network connected by the multiple servers to be managed and the in-band network connected by the execution server are in the same network segment; In response to the out-of-band network connected by the multiple servers to be managed and the in-band network connected by the execution server not being in the same network segment, load a network connection tool on the execution server to establish network communication between the execution server and the multiple servers to be managed through the network connection tool, so that the out-of-band network connected by the multiple servers to be managed and the in-band network connected by the execution server are in the same network segment.
4. The password management method according to claim 3, characterized in that, Before the step of setting the execution server to be connected to the in-band network and setting the multiple servers to be managed to be connected to the out-of-band network, it further includes: Determine whether the Internet protocol addresses corresponding to the baseboard management controllers of the multiple servers to be managed are allocated; In response to the Internet protocol addresses corresponding to the baseboard management controllers of the multiple servers to be managed not being allocated, install the Dynamic Host Configuration Protocol on the execution server and allocate the Internet protocol addresses corresponding to the baseboard management controllers for the multiple servers to be managed based on the Dynamic Host Configuration Protocol.
5. The password management method according to claim 1, wherein, The step of filling in the Internet protocol addresses and the modified baseboard management controller passwords in the baseboard management controller configuration file and copying the baseboard management controller configuration file to the non-target type operating system after installing the virtual machine of the target type includes: Obtain the Internet Protocol addresses, user names, initial Baseboard Management Controller (BMC) passwords, and modified BMC passwords corresponding to the BMCs of multiple servers to be managed; Select any one of the multiple servers to be managed in sequence as the target server to be managed; Write the Internet Protocol address, user name, initial BMC password, and modified BMC password corresponding to the BMC of the target server to be managed to any line in the BMC configuration file; Obtain the BMC configuration file and the script file, copy the BMC configuration file and the script file to the non-target type operating system after installing the virtual machine of the target type, and change the read permission of the BMC configuration file and the script file to executable permission.
6. The password management method according to claim 1, characterized in that, Before the execution server and the network status of the multiple servers to be managed are in a connected state and the firewall status of the multiple servers to be managed is in a connected state, it includes: Use a network diagnostic tool to determine whether the network between the execution server and the multiple servers to be managed is connected; In response to the network status between the execution server and the multiple servers to be managed being in a connected state, run the Intelligent Platform Management Interface (IPMI) command to obtain the server sensor data of the multiple servers to be managed; In response to obtaining the server sensor data of the multiple servers to be managed through the IPMI command, determine that the firewall status of the multiple servers to be managed is in a connected state.
7. The password management method according to claim 1, wherein The modification of the BMC password corresponding to the BMC of the multiple servers to be managed based on the BMC configuration file includes: Obtain the script file from the operating system; Obtain the user name, in response to setting the administrator permission for the user name, run the script file, and automatically modify the initial BMC password corresponding to the BMC of the multiple servers to be managed to the modified BMC password corresponding to the BMC of the multiple servers to be managed.
8. The password management method according to claim 7, characterized in that, The running of the script file includes: Execute the script file in the current directory through the target type script interpreter; In response to the script file running, obtain the output statements during the running of the script in real time, and display the output statements on the execution page of the execution server; In response to the completion of the execution of the script file, export the script execution log, and name the exported script execution log with the script file execution directory and the time of exporting the script execution log.
9. The password management method according to claim 1, wherein, After the modification of the BMC password corresponding to the BMC of the multiple servers to be managed based on the BMC configuration file, it further includes: Select any one of the multiple servers to be managed in sequence as the verification server; Log in to the verification server through the user management command and the modified BMC password corresponding to the verification server; In response to the failure to log in to the verification server through the user management command and the modified BMC password corresponding to the verification server, determine that the modification of the BMC password corresponding to the verification server is unsuccessful.
10. The password management method according to claim 9, wherein After the password modification of the baseboard management controller corresponding to the determination and verification server fails, it includes: Judging whether the password length and password characters corresponding to the modified baseboard management controller of the verification server meet the requirements; In response to the password length and the password characters not meeting the requirements, generating a first warning message, where the first warning message indicates that the password length and the password characters of the verification server do not meet the requirements; In response to the password length and the password characters meeting the requirements, judging whether the user name corresponding to the verification server has administrator privileges; In response to the user name corresponding to the verification server not having administrator privileges, generating a second warning message, where the second warning message indicates that the user name corresponding to the verification server does not have administrator privileges; In response to the user name corresponding to the verification server having administrator privileges, judging whether the firewall status of the verification server is in a connected state; In response to the firewall status of the verification server being in a non-connected state, generating a third warning message, where the third warning message indicates that the firewall status of the verification server is in a non-connected state.
11. The password management method according to claim 1, wherein Modifying the baseboard manager password includes modifying the effective duration identifier, which is composed of the generation time of the modified baseboard management controller password and the modified effective deadline of the modified baseboard management controller password. Modifying the baseboard management controller passwords corresponding to the baseboard management controllers of multiple servers to be managed based on the baseboard management controller configuration file further includes: Obtaining the modified effective duration identifiers for modifying the baseboard manager passwords corresponding to multiple servers to be managed; Obtaining the target modification time for performing the password modification operation on the baseboard management controller passwords of multiple servers to be managed, Sequentially selecting any server to be managed from multiple servers to be managed as the verification server to be managed; Judging whether the target modification time of the verification server to be managed matches the modified effective duration identifier of the verification server to be managed; In response to the modified effective duration identifier corresponding to the verification server to be managed matching the target modification time, adding the verification server to be managed to the cache queue, and performing the password modification operation on the baseboard management controller passwords of the servers in the cache queue; In response to the modified effective duration identifier corresponding to the verification server to be managed not matching the target modification time, adding the verification server to be managed to the allocation queue, and reallocating the modified baseboard management controller password for the servers in the allocation queue.
12. The password management method according to claim 1, wherein The password management method further includes: Obtaining the unique identification code of the baseboard management controller chip and the initial baseboard management controller password of multiple servers to be managed; Dividing the initial baseboard management controller password to obtain multiple sub-initial baseboard management controller passwords; Performing byte flipping on multiple sub-initial baseboard management controller passwords so that the front bytes and the back bytes of multiple sub-initial baseboard management controller passwords are swapped in position, generating multiple flipped passwords; Performing exclusive OR operation on the bytes in multiple flipped passwords to obtain multiple passwords to be concatenated; Concatenating multiple passwords to be concatenated and the unique identification code to obtain the modified baseboard management controller password.
13. A computer device, characterized in that, Includes: A memory for storing a computer program; A processor for implementing the steps of the password management method according to any one of claims 1 to 12 when executing the computer program.
14. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, wherein the computer program implements the steps of the password management method according to any one of claims 1 to 12 when executed by a processor.
15. A computer program product, comprising a computer program, characterized in that, The computer program implements the steps of the password management method according to any one of claims 1 to 12 when executed by a processor.
Citation Information
Patent Citations
Method and system for on-batch setup of BMC (Baseboard Management Controller) user names and passwords
CN107895107A
Batch deployment method and system for server operating systems
CN111371589A
Data recovery method and system for baseboard management controller
CN116795600A
Configuration method of baseboard management controller (BMC) and related equipment
CN118363676A
Automatic creation method and system for BMC user of server and storage medium
CN119960855A