Failed to change the password of ISFUSER on the switch.



Do the following steps to diagnose and report the problem:
  1. Run the following command to get the switch IP address.
    oc get switch mgmt1-rackag5 -o yaml | grep switchIpadress
    Example output:
    switchIpadress: fd8c:215d:178e:c0de:e69d:73ff:fe69:b400
  2. Check connectivity to the switch from one of the compute node using the following steps:
    1. Run the following command to get the node details.
      oc get node
      Example output:
      NAME                                  STATUS                     ROLES                  AGE     VERSION   Ready                      worker                 5d14h   v1.25.14+bcb9a60    Ready,SchedulingDisabled   worker                 9d      v1.25.14+bcb9a60    Ready,SchedulingDisabled   worker                 9d      v1.25.14+bcb9a60    Ready                      control-plane,master   9d      v1.25.14+bcb9a60    Ready                      control-plane,master   9d      v1.25.14+bcb9a60    Ready                      control-plane,master   9d      v1.25.14+bcb9a60
    2. Run the following command to log in to node.
      oc debug node/
      Example output:
      Temporary namespace openshift-debug-svmds is created for debugging node...
      Starting pod/compute-1-ru27rackag5mydomaincom-debug ...
      To use host binaries, run `chroot /host`
      Pod IP:
      If you don't see a command prompt, try pressing enter.
      sh-4.4# ping fd8c:215d:178e:c0de:e69d:73ff:fe69:b400
      PING fd8c:215d:178e:c0de:e69d:73ff:fe69:b400(fd8c:215d:178e:c0de:e69d:73ff:fe69:b400) 56 data bytes
      64 bytes from fd8c:215d:178e:c0de:e69d:73ff:fe69:b400: icmp_seq=1 ttl=64 time=5.48 ms
      64 bytes from fd8c:215d:178e:c0de:e69d:73ff:fe69:b400: icmp_seq=2 ttl=64 time=0.464 ms
      --- fd8c:215d:178e:c0de:e69d:73ff:fe69:b400 ping statistics ---
      2 packets transmitted, 2 received, 0% packet loss, time 1002ms
      rtt min/avg/max/mdev = 0.464/2.971/5.478/2.507 ms
  3. If ping to switch IP is not working, then collect Network switches logs and contact IBM support.
  4. If ping to switch IP works, then run the following commands to get the default username and password.
    oc get secret mgmt1-rackag5-secret -o yaml | grep defaultUserName
    oc get secret mgmt1-rackag5-secret -o yaml | grep defaultUserPasswrd
  5. Decode the username and password obtained from the previous step.
    echo <username/password> | base64 --decode
  6. Try to SSH from one of the compute node using the default credentials.
    ssh cumulus@fd8c:215d:178e:c0de:e69d:73ff:fe69:b400
    Example output:
    The authenticity of host 'fd8c:215d:178e:c0de:e69d:73ff:fe69:b400 (fd8c:215d:178e:c0de:e69d:73ff:fe69:b400)' can't be established.
    ECDSA key fingerprint is SHA256:n9XPEXgyP8A5fgKBCFB4NVwnwwtBYfNnoS5mIu27L7c.
    Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
    Warning: Permanently added 'fd8c:215d:178e:c0de:e69d:73ff:fe69:b400' (ECDSA) to the list of known hosts.
    cumulus@fd8c:215d:178e:c0de:e69d:73ff:fe69:b400's password: 
    Linux mgmt1-rackag5 4.19.0-cl-1-iproc #1 SMP PREEMPT Cumulus 4.19.149-1+cl4.3u1 (2021-01-28) armv7l
    Welcome to NVIDIA Cumulus (R) Linux (R)
    For support and online technical documentation, visit
    The registered trademark Linux (R) is used pursuant to a sublicense from LMI,
    the exclusive licensee of Linus Torvalds, owner of the mark on a world-wide
    Last login: Mon Jan 29 04:11:14 2024 from fd8c:215d:178e:c0de:d8a0:53d6:6eb6:6a55
    Please send these support file(s) to
  7. If the credentials are not working, then collect Network switches logs and contact IBM support.