There should be an option to select the Linux and Unix agent(s) to reset the root password.

P.S. This won't break ssh-relay(vault > account domain) by using ssh keys instead of root credentials(user id, password) as already discussed @ https://ideas.microfocus.com/MFI/pam/Idea/Detail/12656.

Comments

  • Right now this Idea has been gated by a dependency that PAM in and of itself does not have a mechanism to manage passwords for accounts in the credential vault. this had been perceived as a "better together" strategy with IDM and therefore not addressed in the PAM architecture. With the 1H CY'18 release of PAM addressing Service Account Password Management, the framework constructs will be integrated into the infrastructure so that this Idea can then be realized. However the idea itself will not be realized in the release only that the capability that the Idea depends on will be addressed.