Password management method, computer device, readable storage medium and program product
By installing a virtual machine on the operating system and using the intelligent platform management interface tool, batch modification of BMC passwords across operating systems and models is achieved, solving the problem of low BMC password modification efficiency in large-scale server configurations and improving delivery efficiency and reliability.
Patent Information
- Application Number
- CN202510885244.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-30
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2045-06-30
AI Technical Summary
During the configuration of large quantities of servers, existing technologies cannot efficiently modify the baseboard management controller (BMC) password, especially in mixed scenarios with different models and operating systems, which leads to longer delivery time and affects delivery efficiency.
By determining the operating system type, installing a virtual machine of the target type, setting the execution server and the server to be managed to be in the same network segment, obtaining the Internet Protocol address and password of the BMC, using the baseboard management controller configuration file for batch modification, and using the intelligent platform management interface tool to achieve automated password management across operating systems.
It improves the efficiency and reliability of BMC password modification, supports password management under different server models and operating systems, reduces delivery time, and meets the needs of large-scale mixed scenarios.
Smart Images

Figure CN120387159B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a password management method, computer equipment, readable storage medium, and program product. Background Art
[0002] During the server delivery process, the server needs to be initialized according to the customer's initialization requirements, and changing the server's baseboard management controller (BMC) password to a high-strength password is an essential requirement.
[0003] When configuring large batches of servers, addressing customer initialization requirements, single-server operations can significantly extend delivery times. Furthermore, the implementation environment can be severely constrained, further extending delivery times and impacting delivery efficiency. Related technologies utilize batch tools to modify BMC passwords for the same server model. However, this method is limited to the specific server models being configured, typically requiring only the same server model to be configured in a batch. This results in lengthy BMC password modification times and makes it difficult to address the delivery of large batches of servers with different operating systems corresponding to different server models. Summary of the Invention
[0004] The present application provides a password management method, a computer device, a readable storage medium and a program product to solve the technical problem in the related art that it takes a long time to modify the password of a baseboard management controller.
[0005] The present application provides a password management method, including: determining whether an operating system type is a target type, and in response to the operating system type being a non-target type, installing a virtual machine of the target type on the operating system; setting an execution server connected to an in-band network and a plurality of servers to be managed connected to an out-of-band network to be in the same network segment; obtaining Internet Protocol addresses corresponding to baseboard management controllers of the plurality of servers to be managed and modifying the baseboard management controller passwords; filling the Internet Protocol addresses and the modified baseboard management controller passwords in a baseboard management controller configuration file, and copying the baseboard management controller configuration file to the non-target type operating system after the target type virtual machine is installed; and in response to the network status of the execution server and the plurality of servers to be managed being connected and the firewall status of the plurality of servers to be managed being connected, modifying the baseboard management controller passwords corresponding to the baseboard management controllers of the plurality of servers to be managed based on the baseboard management controller configuration file.
[0006] The present application also provides a computer device, comprising: a memory for storing a computer program; and a processor for implementing the steps of the password management method in the following embodiments when executing the computer program.
[0007] Determine whether the operating system type is a target type, and in response to the operating system type being a non-target type, install a virtual machine of the target type on the operating system; set the execution server connected to the in-band network and the multiple servers to be managed connected to the out-of-band network to be in the same network segment; obtain the Internet Protocol addresses corresponding to the baseboard management controllers of the multiple servers to be managed and modify the baseboard management controller passwords; fill in the Internet Protocol addresses and the modified baseboard management controller passwords in the baseboard management controller configuration file, and copy the baseboard management controller configuration file to the non-target type operating system after installing the target type virtual machine; in response to the network status of the execution server and the multiple servers to be managed being connected and the firewall status of the multiple servers to be managed being connected, modify the baseboard management controller passwords corresponding to the baseboard management controllers of the multiple servers to be managed based on the baseboard management controller configuration file.
[0008] The present application also provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of the password management method in the following embodiment are implemented.
[0009] Determine whether the operating system type is a target type, and in response to the operating system type being a non-target type, install a virtual machine of the target type on the operating system; set the execution server connected to the in-band network and the multiple servers to be managed connected to the out-of-band network to be in the same network segment; obtain the Internet Protocol addresses corresponding to the baseboard management controllers of the multiple servers to be managed and modify the baseboard management controller passwords; fill in the Internet Protocol addresses and the modified baseboard management controller passwords in the baseboard management controller configuration file, and copy the baseboard management controller configuration file to the non-target type operating system after installing the target type virtual machine; in response to the network status of the execution server and the multiple servers to be managed being connected and the firewall status of the multiple servers to be managed being connected, modify the baseboard management controller passwords corresponding to the baseboard management controllers of the multiple servers to be managed based on the baseboard management controller configuration file.
[0010] The present application also provides a computer program product, including a computer program, which implements the steps of the password management method in the following embodiments when the computer program is executed by a processor.
[0011] Determine whether the operating system type is a target type, and in response to the operating system type being a non-target type, install a virtual machine of the target type on the operating system; set the execution server connected to the in-band network and the multiple servers to be managed connected to the out-of-band network to be in the same network segment; obtain the Internet Protocol addresses corresponding to the baseboard management controllers of the multiple servers to be managed and modify the baseboard management controller passwords; fill in the Internet Protocol addresses and the modified baseboard management controller passwords in the baseboard management controller configuration file, and copy the baseboard management controller configuration file to the non-target type operating system after installing the target type virtual machine; in response to the network status of the execution server and the multiple servers to be managed being connected and the firewall status of the multiple servers to be managed being connected, modify the baseboard management controller passwords corresponding to the baseboard management controllers of the multiple servers to be managed based on the baseboard management controller configuration file.
[0012] The password management method provided by the present application comprises the following steps: determining whether the operating system type is a target type, and in response to the operating system type being a non-target type, installing a target type virtual machine on the operating system; setting an execution server connected to an in-band network and multiple servers to be managed connected to an out-of-band network to be in the same network segment; obtaining the Internet Protocol addresses corresponding to the baseboard management controllers of the multiple servers to be managed and modifying the baseboard management controller passwords; filling the Internet Protocol addresses and the modified baseboard management controller passwords in a baseboard management controller configuration file, and copying the baseboard management controller configuration file to the non-target type operating system after installing the target type virtual machine; and in response to the execution server and the multiple servers to be managed being in a connected state in terms of network status and the multiple servers to be managed being in a connected state in terms of firewall status, modifying the baseboard management controller passwords corresponding to the baseboard management controllers of the multiple servers to be managed based on the baseboard management controller configuration file. Therefore, the method supports password modification of baseboard management controllers under different operating systems corresponding to different server models, and performs the baseboard management controller password modification operation when the execution server and the multiple servers to be managed are in a connected state in terms of network status and the multiple servers to be managed being in a connected state in terms of firewall status, thereby improving the efficiency and reliability of baseboard management controller password management. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] In order to more clearly illustrate the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0014] Figure 1 A flowchart of a password management method provided in one embodiment of the present application;
[0015] Figure 2 A flowchart of a password management method provided in another embodiment of the present application;
[0016] Figure 3 A schematic diagram of the structure of a password management device provided in one embodiment of the present application;
[0017] Figure 4 This is a diagram of the internal structure of a computer device provided in one embodiment of the present application. DETAILED DESCRIPTION
[0018] The following will be combined with the accompanying drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments of this application, all other embodiments obtained by ordinary technicians in this field without making any creative work are within the scope of protection of this application.
[0019] It should be noted that, in the description of this application, the terms "comprises," "includes," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. The terms "first," "second," etc., in this application are used to distinguish similar objects, and are not used to describe a particular order or sequence.
[0020] Currently, servers have been widely used in various industries, covering finance, communications, transportation and many other industries.
[0021] A BMC is a hardware management chip independent of the operating system, providing out-of-band management capabilities. This allows remote operation even if the server is shut down or the operating system crashes. Its core functions include hardware monitoring and management, remote control, fault diagnosis and recovery, and security auditing. The BMC has underlying control over the server, and its password is the core of security protection. BMC user passwords are primarily used to prevent unauthorized access (high-risk permissions: If an attacker obtains the BMC password, they can remotely control the server power supply, modify firmware, steal data, or insert malware. Hidden attack surface: BMCs are often exposed through independent network interfaces, and weak passwords can serve as a springboard for intrusion into the internal network); ensure business continuity (risk of malicious operation: Password leakage can lead to unauthorized server shutdown, configuration tampering, or firmware corruption, causing service interruption. Physical security supplement: Even with strict physical protection in the computer room, a BMC password leak can still allow an attacker to remotely carry out damage); meet compliance requirements (most security standards (such as PCI DSS and ISO 27001) require strict management of access rights to out-of-band management interfaces, and strong passwords are a basic requirement); and defend against supply chain attacks (avoiding default passwords (such as admin / admin) to prevent automated attack tools that exploit factory credentials). The BMC is the "last line of defense" for server hardware management. Its interface provides powerful out-of-band management capabilities, but password leakage can have catastrophic consequences. Strong password policies, network isolation, and continuous monitoring can significantly reduce security risks and ensure stable server operations.
[0022] During the delivery process, according to the customer's initialization requirements, changing the server BMC user to a strong password is an essential requirement. When configuring large quantities of servers, performing individual operations to meet customer initialization requirements can significantly extend delivery time and impose significant constraints on the implementation environment, further extending delivery time and impacting delivery efficiency.
[0023] In the first related technology, the password of the BMC corresponding user is mainly modified through the BMC web interface. However, this method can only be used for single-machine operations. It cannot be completed quickly for large-scale sites that need to modify BMC passwords, which seriously prolongs the delivery cycle. In addition, this method requires each server to log in to the BMC web management interface. Some confidential customers may not be able to provide the corresponding information, making configuration impossible.
[0024] In the second related technology, the passwords of users corresponding to the BMC are modified in batches through batch tools. However, the environment in which this method is implemented is limited. Although the BMC passwords can be modified in batches, this method is limited to the models to be operated. Generally, only servers of the same model can be configured in a batch, and mixed scenarios cannot be operated in the same batch.
[0025] As you can see, there are currently two methods for configuring BMC user passwords: per-server configuration through the BMC web interface and per-server modification through user functions. This method is time-consuming, which can extend delivery times for large-volume deliveries and fail to efficiently meet customer requirements. There are also batch tools for modifying BMC passwords for the same server model, but this method is limited to the server models being operated on. Generally, only servers of the same model can be configured in a batch, and mixed scenarios cannot be performed in the same batch.
[0026] In response to the above technical issues, such as Figure 1 As shown, an embodiment of the present application provides a password management method, which specifically includes the following steps:
[0027] Step 101: Determine whether the operating system type is a target type. In response to the operating system type being a non-target type, install a virtual machine of the target type on the operating system.
[0028] Specifically, the operating system type is obtained, and it is determined whether the operating system type is a target type operating system; the target type operating system is an operating system that supports shell scripts; in response to the operating system type being a non-target type operating system, a target type virtual machine is installed on the operating system.
[0029] Specifically, the running script in this application is a shell script, which can subsequently automatically execute the password modification operation of the baseboard management controller of any server according to the running script. Here, the operating system type is first obtained to determine whether the operating system type is an operating system type that supports shell scripts. When the operating system type is a non-target type, it is considered that the current operating system does not support shell scripts, and it is necessary to install a target type virtual machine on the current operating system to enable the operating system to support shell scripts. The target type virtual machine here can be a Linux virtual machine. The Linux virtual machine is a special software running on the host operating system, which can simulate a complete computer hardware system environment.
[0030] Currently, mainstream operating systems are Windows and Linux. When using Linux, scripts can be run on mainstream Linux distributions such as CentOS, Red Hat, and Ubuntu. If the operating system is Windows, shell scripts can also be executed by installing a Linux virtual machine. This allows for scalability of the execution server and multiple managed servers in either Windows or Linux environments.
[0031] In this way, there is no need to use the customer environment. Operators only need to install virtual machines on their own environment and build a Linux system environment to perform batch operations. If the operating environment is provided by the customer, this invention also covers mainstream system environments based on Linux systems, including CentOS, Redhat, and Kylin, maximizing coverage of the delivery site.
[0032] Step 102: Set the execution server connected to the in-band network and the multiple servers to be managed connected to the out-of-band network to be in the same network segment.
[0033] Specifically, before setting up an execution server to connect to an in-band network and setting up multiple servers to be managed to connect to an out-of-band network, it also includes: determining whether the Internet Protocol addresses corresponding to the baseboard management controllers of the multiple servers to be managed are allocated; in response to the Internet Protocol addresses corresponding to the baseboard management controllers of the multiple servers to be managed not being allocated, installing the Dynamic Host Configuration Protocol on the execution server, and allocating the Internet Protocol addresses corresponding to the baseboard management controllers to the multiple servers to be managed based on the Dynamic Host Configuration Protocol.
[0034] First, determine whether the server to be managed has a network environment (that is, whether the server to be managed has Dynamic Host Configuration Protocol installed). If the server to be managed does not have a network environment, establish a network environment by using the server executing the command as a DHCP host (Dynamic Host Configuration Protocol) so that the server to be managed can automatically obtain its corresponding baseboard management controller Internet Protocol address. If the server to be managed has a network environment, connect the executing server directly to the in-band network and the server to be managed to the out-of-band network. Dynamic Host Configuration Protocol is a network protocol for local area networks. It refers to a range of IP addresses controlled by a server, and when a client logs in to the server, it automatically obtains the IP address and subnet mask assigned by the server.
[0035] Further, it is determined whether the out-of-band network connected to the multiple servers to be managed and the in-band network connected to the execution server are in the same network segment; in response to the fact that the out-of-band network connected to the multiple servers to be managed and the in-band network connected to the execution server are not in the same network segment, a network connection tool is loaded on the execution server to establish network communication between the execution server and the multiple servers to be managed through the network connection tool, so that the out-of-band network connected to the multiple servers to be managed and the in-band network connected to the execution server are in the same network segment.
[0036] Step 103: Obtain the Internet Protocol addresses corresponding to the baseboard management controllers of multiple servers to be managed and modify the baseboard management controller passwords; fill in the Internet Protocol addresses and modified baseboard management controller passwords in the baseboard management controller configuration file, and copy the baseboard management controller configuration file to the non-target type operating system after installing the target type virtual machine.
[0037] Specifically, the Internet Protocol addresses, user names, initial baseboard management controller passwords and modified baseboard management controller passwords corresponding to the baseboard management controllers of multiple servers to be managed are obtained; any one of the multiple servers to be managed is selected as the target server to be managed in turn; the Internet Protocol address, user name, initial baseboard management controller password and modified baseboard management controller password corresponding to the baseboard management controller of the target server to be managed are written into any line in the baseboard management controller configuration file.
[0038] For example, the information of each server to be managed can be written into each line of the BMC configuration file in the execution server according to the format of the BMC's corresponding Internet Protocol address, user name, initial BMC password, and modified BMC password. The information of multiple servers to be managed can be displayed in separate lines. For reference, see the following:
[0039] cat< <eof>bmc_list.csv
[0040] 192.168.1.101,admin,old password 1,new password 1
[0041] 192.168.1.102, root, old password 2, new password 2
[0042] 192.168.1.103, Administrator, Old Password 3, New Password 3
[0043] EOF
[0044] As you can see, the first column in the BMC configuration file contains the BMC's Internet Protocol address (BMC IP), the second column contains the BMC username, the third column contains the old password (the initial BMC password), and the fourth column contains the new password (the changed BMC password). Each server occupies one line, with data separated by commas (in English). Ensure that the information is correct. For example, IP: 10.49.32.45, username: joker5, current password (old password): jszx2024Niu!, new password: Inspur5%.
[0045] Further obtain the baseboard management controller configuration file and script file, copy the baseboard management controller configuration file and script file to the non-target type operating system after installing the target type virtual machine, and change the baseboard management controller configuration file and script file from readable permission to executable permission.
[0046] In this application, the execution server can construct a shell script. A shell script is a scripting language based on shell commands, which is used to automate the execution of a series of commands. The shell script can include the config.sh command (run script command) and bmc_list.txt (baseboard management controller configuration file). Specifically, after the execution server completes the installation of the script software, all the attached files (the attached files include the config.sh command (run script command) and bmc_list.txt (baseboard management controller configuration file)) can be copied to the current operating system and given executable permissions. In this way, the running script can be executed under multiple operating systems.
[0047] Step 104: In response to the execution server and the multiple servers to be managed having a connected network state and the multiple servers to be managed having a connected firewall state, modify the baseboard management controller passwords corresponding to the baseboard management controllers of the multiple servers to be managed based on the baseboard management controller configuration file.
[0048] Specifically, the network status of the execution server and the multiple servers to be managed is obtained; whether the network of the execution server and the multiple servers to be managed is determined through a network diagnostic tool; in response to the network status of the execution server and the multiple servers to be managed being in a connected state, the intelligent platform management interface command is run to obtain the server sensor data of the multiple servers to be managed; in response to the server sensor commands of the multiple servers to be managed obtained through the intelligent platform management interface command, it is determined that the firewall status of the multiple servers to be managed is in a connected state.
[0049] This application also ensures network connectivity between the execution server and each managed server. To this end, based on the baseboard management controller configuration file, it executes intelligent platform management interface commands to obtain the connection status of each managed server's transmission protocol port (the firewall status of multiple managed servers). It also executes the ping command (a network diagnostic tool) to obtain the data transmission status of each managed server. It should be noted that the intelligent platform management interface tool command and the ping command are stored in the execution script. Ping sends an ICMP (Internet Control Messages Protocol) echo request message to the destination and reports whether the expected ICMP echo (ICMP echo reply) was received. It is used to check network connectivity and connection speed.
[0050] In a specific implementation, the network connectivity between the execution server (operation host) and multiple servers to be managed is checked and confirmed using the following two steps: 1. Confirm the network connectivity (data transmission status of each server to be managed) through the ping command: 2. Confirm that the server's UDP port 623 is open (firewall policy) through the intelligent platform management interface instruction. Specifically, you can confirm whether the port is open through the command return value. At the same time, ensure that the BMC user who changes the password has administrator privileges. Non-administrator privileges cannot obtain the corresponding server information. In addition, the currently configured BMC user is also required to have administrator privileges in the configuration script, otherwise the execution of obtaining server information will fail.
[0051] Specifically, a script file is obtained from the operating system; a user name is obtained, administrator permissions are set in response to the user name, and the script file is run to automatically modify the initial baseboard management controller passwords corresponding to the baseboard management controllers of multiple servers to be managed to modified baseboard management controller passwords corresponding to the baseboard management controllers of multiple servers to be managed.
[0052] Among them, running the script file includes: executing the script file in the current directory through the target type script interpreter; in response to the running of the script file, obtaining the output statements in the script running process in real time, and displaying the output statements on the execution page of the execution server; in response to the completion of the script file execution, exporting the script execution log, and naming the exported script execution log with the script file execution directory and the exported script execution log time.
[0053] In this application, administrator permissions are set for the user name of the baseboard management controller. Only when the user name has administrator permissions can important information recording the system configuration be obtained and the script file can be run. The script file will be used to batch modify the passwords of the baseboard management controllers of multiple servers to be managed.
[0054] When running a script file, this application can also record the output statements in the script running process in real time and display them on the execution interface of the execution server. After the script file execution is completed, you can set to export the script execution log. The script execution log of each server will be recorded in the export file. In the log file, the corresponding operation log of each server will be exported according to the corresponding IP information, and the cause of failure can be quickly located for failed operations.
[0055] Execute the following command in the current directory: "config.sh". The execution log will be displayed on the execution page. After the execution is completed, the execution log will be automatically exported to the directory where the current script is located, and the name will be suffixed with the time.
[0056] In one embodiment, the present application is configured to obtain the unique identification codes of the baseboard management controller chips of multiple servers to be managed and the initial baseboard management controller password; divide the initial baseboard management controller password to obtain multiple sub-initial baseboard management controller passwords; perform byte flipping on the multiple sub-initial baseboard management controller passwords so that the front bytes and the back bytes of the multiple sub-initial baseboard management controller passwords are swapped to generate multiple flipped passwords; perform OR operations on the bytes in the multiple flipped passwords to obtain multiple passwords to be spliced; splice the multiple passwords to be spliced and the unique identification code to obtain a modified baseboard management controller password.
[0057] Specifically, the initial baseboard management controller password can be divided into multiple parts to obtain multiple sub-initial baseboard management controller passwords, and each sub-initial baseboard management controller password in the multiple sub-initial baseboard management controller passwords is byte-flipped to swap the positions of the front bytes and the back bytes of each sub-initial baseboard management controller password to generate multiple flipped passwords, and each byte in each flipped password is ORed to obtain multiple passwords to be spliced, and the multiple passwords to be spliced are spliced with the unique identification code to obtain the modified baseboard management controller password. In this way, the diversity of formulating the modified baseboard management controller password is enriched, and at the same time, the unique identification code is retained when specifying the modified baseboard management controller password. While increasing the complexity of modifying the baseboard management controller password, the characteristics of the baseboard management controller are retained.
[0058] In one embodiment, after modifying the baseboard management controller passwords corresponding to the baseboard management controllers of multiple servers to be managed based on the baseboard management controller configuration file, it also includes: selecting any one of the multiple servers to be managed as a verification server in turn; logging into the verification server through a user management command and the modified baseboard management controller password corresponding to the verification server; in response to unsuccessful logging into the verification server through the user management command and the modified baseboard management controller password corresponding to the verification server, determining that the baseboard management controller password corresponding to the verification server has been modified unsuccessfully.
[0059] This application also sets up a verification mechanism. After the baseboard management controller password modification operation is completed, the new password will be automatically used, that is, the baseboard management controller password is modified to log in. If the login fails, the execution failure will be prompted in the log, and the specific server to be managed can be confirmed according to the baseboard management controller network protocol address (BMC IP) to achieve rapid fault location.
[0060] After determining that the baseboard management controller password modification corresponding to the verification server is unsuccessful, it is possible to determine whether the password length and password characters corresponding to the modified baseboard management controller password of the verification server meet the requirements; in response to the password length and password characters not meeting the requirements, a first alarm message is generated, and the first alarm message indicates that the password length and password characters of the verification server do not meet the requirements; in response to the password length and password characters meeting the requirements, it is determined whether the user name corresponding to the verification server is set with administrator authority; in response to the user name corresponding to the verification server not being set with administrator authority, a second alarm message is generated, and the second alarm message indicates that the user name corresponding to the verification server is not set with administrator authority; in response to the user name corresponding to the verification server being set with administrator authority, it is determined whether the firewall status of the verification server is connected; in response to the firewall status of the verification server being disconnected, a third alarm message is generated, and the third alarm message indicates that the firewall status of the verification server is disconnected.
[0061] After determining that the BMC password modification corresponding to the verification server is unsuccessful, the length of the password corresponding to the BMC password modification and whether there are any illegal characters in the characters that make up the password can be determined in turn. For example, whether the password is 12 characters long, and illegal characters may include the space bar. The illegal characters and password length here can be set by the operator. If there is an error in the verification password, an alarm will be issued immediately. If there is no error in the verification password, the next step of verification will be carried out, including determining whether the user name is set with administrator privileges, whether the server's firewall is connected, etc., until the reason for the unsuccessful BMC password modification is found, and a corresponding alarm message is generated based on the reason, so that the user can clearly and clearly view the reason for the unsuccessful BMC password modification.
[0062] In one embodiment, modifying the baseboard manager password includes modifying the effective time identifier, and the effective time identifier is composed of the baseboard management controller password generation time and the effective expiration time of the baseboard management controller password. Modifying the baseboard management controller passwords corresponding to the baseboard management controllers of multiple servers to be managed based on the baseboard management controller configuration file also includes: obtaining the effective time identifiers for modifying the baseboard manager passwords corresponding to multiple servers to be managed; obtaining the target modification time for performing the password modification operation on the baseboard management controller passwords of multiple servers to be managed, and selecting any one of the multiple servers to be managed as the test server to be managed in turn; judging whether the target modification time of the test server to be managed matches the effective time identifier for modifying the test server to be managed; in response to the effective time identifier corresponding to the test server to be managed matching the target modification time, adding the test server to be managed to the cache queue, and performing the password modification operation for the baseboard management controller passwords of the servers in the cache queue; in response to the effective time identifier corresponding to the test server to be managed not matching the target modification time, adding the test server to be managed to the allocation queue, and reallocating the baseboard management controller password modification for the servers in the allocation queue. In this way, by performing differentiated processing based on whether the target modification time of the server to be managed matches the modification validity period identifier of the server to be managed, the server to be managed that matches is added to the cache queue. The server to be managed that does not match is added to the allocation queue, ensuring that password changes strictly comply with security policy requirements.
[0063] This application also sets a modification validity period identifier for modifying the baseboard management controller password. The modification validity period identifier here is used to calibrate the validity period of modifying the baseboard management controller password. If the execution time of the baseboard management controller password modification operation corresponding to any modification baseboard management controller password matches the validity period identifier corresponding to the password, that is, the execution time of the baseboard management controller password modification operation corresponding to the modification baseboard management controller password is within the time range of the validity period identifier corresponding to the password, it means that when the modification operation is executed, the modification baseboard management controller password has not expired, the unexpired modification baseboard management controller password is added to the cache queue, and the password modification operation is performed on the baseboard management controller password of the server in the cache queue. When the execution time of the baseboard management controller password modification operation corresponding to the modification baseboard management controller password is not within the time range of the validity period identifier corresponding to the password, it is considered that the modification baseboard management controller password has expired, the server corresponding to the modification baseboard management controller password is added to the allocation queue, and the modification baseboard management controller password is reallocated to the server in the allocation queue. In this way, through time-driven password management, while ensuring security, the operation and maintenance complexity is significantly reduced, which is particularly suitable for ultra-large-scale data center scenarios.
[0064] In this application, by using the shell language to develop and run scripts, with the help of the intelligent platform management interface tool system tool, it can cover the configuration environment of most operating systems. The intelligent platform management interface tool has high compatibility and reliability with existing BMCs and meets the conditions for batch execution; at the same time, by using the intelligent platform management interface tool, on-site batch operations of mixed multiple models can be performed. For on-site environments with multiple models, this script can be executed once to complete the password modification of the corresponding BMC user; and the operation log during configuration is retained and the operation results are verified to facilitate tracing of the execution results.
[0065] In one embodiment, since the Intelligent Platform Management Interface Tool (IPMITOOL) has a Windows version, it can be run in a Windows environment through batch processing. Specifically, the BMC configuration files for multiple servers to be managed are obtained, and the Intelligent Platform Management Interface Tool is invoked through batch processing. The BMC password modification information, including the modification validity period, is stored. To modify multiple user passwords on a single server, the corresponding parameters are simply added to the BMC configuration file. This enables complete BMC management capabilities in a Windows environment, reducing enterprise operation and maintenance costs. Furthermore, a single execution can batch-process password modification operations for multiple BMCs, improving BMC password modification efficiency.
[0066] See also Figure 2 In order to better describe the password management method provided by this application, a specific example is given for illustration:
[0067] S1: Build an operating environment (Linux operating environment, specifically an operating environment of a Linux distribution such as CentOS, Redhat, or Ubuntu).
[0068] Determine whether the operating system type supports shell scripts. If the operating system type is the target type, the current operating system is considered to support shell scripts. A virtual machine of the target type needs to be installed on the current operating system to enable the operating system to support shell scripts. The target virtual machine can be a Linux virtual machine. See step 101 for details.
[0069] S2: Connect multiple managed servers and the operation end host (execution server) to the same network environment; the execution server is connected to the in-band network, and the managed servers are connected to the out-of-band network.
[0070] The execution server connected to the in-band network and the multiple servers to be managed connected to the out-of-band network are set to be in the same network segment, see the description of step 102 for details.
[0071] S3: Power on the managed server to ensure that the BMC is started and that the BMC IP address can be obtained. Then, write the BMC IP information corresponding to the service to be configured into the "bmc_list.txt" file as required.
[0072] Obtain the Internet Protocol addresses corresponding to the baseboard management controllers of multiple servers to be managed and modify the baseboard management controller passwords; fill in the Internet Protocol addresses and modified baseboard management controller passwords in the baseboard management controller configuration file, and copy the baseboard management controller configuration file to the non-target type operating system after installing the target type virtual machine. See the description of step 103 for details.
[0073] S4: The executing server executes ping and intelligent platform management interface tool commands to confirm the return value (confirming the network status between the executing server and the multiple servers to be managed and the firewall status of the multiple servers to be managed).
[0074] The network status between the execution server and the multiple servers to be managed and the firewall status of the multiple servers to be managed are determined according to the return value of the intelligent platform management interface tool command. When the return value reflects that the network status between the execution server and the multiple servers to be managed and / or the firewall status of the multiple servers to be managed are not connected, the network status between the disconnected execution server and the multiple servers to be managed and / or the firewall status of the multiple servers to be managed are rechecked and reconfigured.
[0075] S5: Execute the batch script config.sh (run the script to modify the baseboard management controller passwords corresponding to the baseboard management controllers of multiple servers to be managed based on the baseboard management controller configuration file)
[0076] In response to the network status between the execution server and the multiple servers to be managed being connected and the firewall status of the multiple servers to be managed being connected, the baseboard management controller passwords corresponding to the baseboard management controllers of the multiple servers to be managed are modified based on the baseboard management controller configuration file, see the description of step 104 for details.
[0077] S6: Determine whether the baseboard management controller password is successfully modified.
[0078] Specifically, after a BMC password change is completed, the new password is automatically used. If the login fails, a log message will indicate the failure. If the password change is unsuccessful, the script execution log can be obtained and used to troubleshoot the issue. The script can then be re-run to automatically execute the BMC password change operation on any server.
[0079] The embodiment of the present application provides a password management device, which is specifically as follows: Figure 3 As shown, the password management device includes: a judgment module 20, a setting module 21, a writing module 22 and a modification module 23.
[0080] The judgment module 20 is configured to judge whether the operating system type is a target type, and in response to the operating system type being a non-target type, install a virtual machine of the target type on the operating system.
[0081] The setting module 21 is used to set the execution server connected to the in-band network and the multiple servers to be managed connected to the out-of-band network to be in the same network segment.
[0082] The writing module 22 is used to obtain the Internet Protocol addresses corresponding to the baseboard management controllers of multiple servers to be managed and to modify the baseboard management controller passwords; fill in the Internet Protocol addresses and the modified baseboard management controller passwords in the baseboard management controller configuration file, and copy the baseboard management controller configuration file to the non-target type operating system after the target type virtual machine is installed.
[0083] The modification module 23 is used to modify the baseboard management controller passwords corresponding to the baseboard management controllers of the multiple servers to be managed based on the baseboard management controller configuration file in response to the network status between the execution server and the multiple servers to be managed being connected and the firewall status of the multiple servers to be managed being connected.
[0084] like Figure 4 As shown, an embodiment of the present application further provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any one of the above password management method embodiments.
[0085] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. The computer program is configured to execute the steps of any of the above-mentioned password management method embodiments when running.
[0086] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disk.
[0087] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be judged to be beyond the scope of this application.
[0088] The above describes in detail the password management method provided by this application. This document uses specific examples to illustrate the principles and implementation methods of this application. The description of the above examples is intended only to facilitate understanding of the method and core concepts of this application. It should be noted that those skilled in the art may make various improvements and modifications to this application without departing from the principles of this application, and such improvements and modifications also fall within the scope of protection of this application.< / eof>
Claims
1. A password management method, characterized in that: The password management method includes: determining whether the operating system type is a target type, and in response to the operating system type being a non-target type, installing a virtual machine of the target type on the operating system; Set the execution server connected to the in-band network and multiple managed servers connected to the out-of-band network to be in the same network segment; Obtain Internet Protocol addresses corresponding to baseboard management controllers of multiple servers to be managed and modify baseboard management controller passwords; fill the Internet Protocol addresses and the modified baseboard management controller passwords in a baseboard management controller configuration file, obtain a run script command, and copy the baseboard management controller configuration file and the run script command to a non-target type operating system after installing a target type virtual machine, and set executable permissions for the baseboard management controller configuration file and the run script command to enable the run script to be executable under multiple operating systems; In response to the network status between the execution server and the multiple servers to be managed being connected and the firewall status of the multiple servers to be managed being connected, modifying the baseboard management controller passwords corresponding to the baseboard management controllers of the multiple servers to be managed based on the baseboard management controller configuration file; Among them, modifying the baseboard management controller passwords corresponding to the baseboard management controllers of multiple servers to be managed based on the baseboard management controller configuration file includes: obtaining a script file from the operating system; obtaining a user name, setting administrator permissions in response to the user name, running the script file, and automatically modifying the initial baseboard management controller passwords corresponding to the baseboard management controllers of multiple servers to be managed to modified baseboard management controller passwords corresponding to the baseboard management controllers of multiple servers to be managed.
2. The password management method according to claim 1, characterized in that: The determining whether the operating system type is a target type, and in response to the operating system type being a non-target type, installing a target type virtual machine on the operating system includes: Obtaining the operating system type, and determining whether the operating system type is a target type operating system; the target type operating system is an operating system that supports shell scripts; In response to the operating system type being a non-target type operating system, a target type virtual machine is installed on the operating system.
3. The password management method according to claim 1, wherein: The setting of the execution server connected to the in-band network and the multiple servers to be managed connected to the out-of-band network being in the same network segment includes: Set up the execution server to connect to the in-band network, and set up multiple servers to be managed to connect to the out-of-band network; Determining whether the out-of-band network connected to the multiple servers to be managed and the in-band network connected to the execution server are in the same network segment; In response to the fact that the out-of-band network connected to the multiple servers to be managed and the in-band network connected to the execution server are not in the same network segment, a network connection tool is loaded on the execution server to establish network communication between the execution server and the multiple servers to be managed through the network connection tool, so that the out-of-band network connected to the multiple servers to be managed and the in-band network connected to the execution server are in the same network segment.
4. The password management method according to claim 3, characterized in that: Before the setting of connecting the execution server to the in-band network and connecting the plurality of servers to be managed to the out-of-band network, the method further includes: Determining whether Internet protocol addresses corresponding to baseboard management controllers of multiple servers to be managed are allocated; In response to the Internet protocol addresses corresponding to the baseboard management controllers of the multiple servers to be managed not being allocated, a dynamic host configuration protocol is installed on the execution server, and the Internet protocol addresses corresponding to the baseboard management controllers are allocated to the multiple servers to be managed based on the dynamic host configuration protocol.
5. The password management method according to claim 1, wherein: Filling the Internet Protocol address and the modified baseboard management controller password in the baseboard management controller configuration file includes: Obtaining Internet protocol addresses, user names, initial baseboard management controller passwords, and modified baseboard management controller passwords corresponding to baseboard management controllers of multiple servers to be managed; Selecting any one of the servers to be managed as a target server to be managed from the multiple servers to be managed in sequence; Write the Internet Protocol address, user name, initial baseboard management controller password, and modified baseboard management controller password corresponding to the baseboard management controller of the target server to be managed into any line in the baseboard management controller configuration file.
6. The password management method according to claim 1, wherein: The method includes, in response to the network status between the execution server and the plurality of servers to be managed being connected and the firewall status of the plurality of servers to be managed being connected: Determine, by a network diagnostic tool, whether the execution server is connected to the networks of the plurality of servers to be managed; In response to the network status between the execution server and the plurality of servers to be managed being in a connected state, executing an intelligent platform management interface command to obtain server sensor data of the plurality of servers to be managed; In response to acquiring server sensor data of a plurality of servers to be managed through an intelligent platform management interface command, it is determined that the firewall states of the plurality of servers to be managed are in a connected state.
7. The password management method according to claim 1, wherein: The running script file includes: Execute the script file in the current directory through the target type script interpreter; In response to the script file running, the output statements in the script running process are obtained in real time, and the output statements are displayed on the execution page of the execution server; In response to the completion of the script file execution, the script execution log is exported, and the exported script execution log is named according to the script file execution directory and the time when the script execution log is exported.
8. The password management method according to claim 1, wherein: After modifying the baseboard management controller passwords corresponding to the baseboard management controllers of the plurality of servers to be managed based on the baseboard management controller configuration file, the method further includes: Selecting any one of the servers to be managed as a verification server from the multiple servers to be managed in sequence; Log in to the verification server through the user management command and the corresponding change baseboard management controller password of the verification server; In response to failure in logging into the verification server through the user management command and modifying the baseboard management controller password corresponding to the verification server, it is determined that modification of the baseboard management controller password corresponding to the verification server is unsuccessful.
9. The password management method according to claim 8, characterized in that: After determining that the password of the baseboard management controller corresponding to the verification server is unsuccessful, the method includes: Determine whether the password length and password characters corresponding to the baseboard management controller password modification of the verification server meet the requirements; In response to the password length and the password characters not meeting the requirements, generating a first warning message, the first warning message indicating that the password length and the password characters of the verification server do not meet the requirements; In response to the password length and the password characters meeting the requirements, determining whether the user name corresponding to the verification server is set with administrator authority; In response to the user name corresponding to the verification server not having administrator authority set, generating second alarm information, the second alarm information indicating that the user name corresponding to the verification server does not have administrator authority set; In response to setting administrator authority for the user name corresponding to the verification server, determining whether the firewall status of the verification server is connected; In response to the firewall status of the verification server being a disconnected state, third alarm information is generated, where the third alarm information indicates that the firewall status of the verification server is a disconnected state.
10. The password management method according to claim 1, wherein: Modifying the baseboard manager password includes modifying the effective duration identifier, wherein the modification effective duration identifier is composed of the modification baseboard management controller password generation time and the modification effective expiration time of the baseboard management controller password. Modifying the baseboard management controller passwords corresponding to the baseboard management controllers of multiple servers to be managed based on the baseboard management controller configuration file also includes: Obtaining a modification validity period identifier for modifying the baseboard manager password corresponding to multiple servers to be managed; Get the target modification time of the baseboard management controller password of multiple servers to be managed and perform the password modification operation. Selecting any one of the servers to be managed as a test server to be managed from the multiple servers to be managed in sequence; Determine whether the target modification time of the server to be managed matches the modification validity duration identifier of the server to be managed; In response to the verification that the modification effective time length identifier corresponding to the server to be managed matches the target modification time, the server to be managed is added to the cache queue, and a password modification operation is performed for the baseboard management controller password of the server in the cache queue; In response to the modification effective duration identifier corresponding to the checked server to be managed not matching the target modification time, the checked server to be managed is added to an allocation queue, and the baseboard management controller password is reallocated and modified for the servers in the allocation queue.
11. The password management method according to claim 1, wherein: The password management method further includes: Obtaining unique identification codes and initial baseboard management controller passwords of multiple servers to be managed; Dividing the initial baseboard management controller password to obtain a plurality of sub-initial baseboard management controller passwords; Byte flipping is performed on the plurality of sub-initial baseboard management controller passwords so that the positions of the first bytes and the second bytes of the plurality of sub-initial baseboard management controller passwords are swapped to generate a plurality of flipped passwords; Performing OR operations on the bytes in multiple flipped passwords to obtain multiple passwords to be spliced; Multiple passwords to be spliced and unique identification codes are spliced together to obtain the modified baseboard management controller password.
12. A computer device, characterized in that: include: memory for storing computer programs; A processor, configured to implement the steps of the password management method according to any one of claims 1 to 11 when executing the computer program.
13. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the password management method according to any one of claims 1 to 11.
14. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the password management method according to any one of claims 1 to 11 are implemented.
Citation Information
Patent Citations
Batch deployment method and system for server operating systems
CN111371589A
Automatic creation method and system for BMC user of server and storage medium
CN119960855A
Server configuration method and device, electronic equipment, storage medium and product
CN120166040A