Hi everyone,
This is my first post. Enjoy.
This procedure is to do a Password Recovery of the admin account.
The procedure is similar to the one specified in sk92663, but with some changes. I am not modify any system files.
Tested in R81, R81.10.
Not test in R80.XX, buy i think will be work
Prerequisites:
- live linux CD (in my case i will be use ubuntu iso)
- Another virtual, server or PC with linux (Any distro)
- "Another linux" and CheckPoint Management must have network connection.
1) boot live linux,
data:image/s3,"s3://crabby-images/7f4d6/7f4d6c4a1ec09679503f4722d7de20d74db91e4b" alt="mnocciolino_0-1699292465222.png mnocciolino_0-1699292465222.png"
2) Preparing "Another linux"
Generate the id_rsa, with the following command
ssh-keygen
data:image/s3,"s3://crabby-images/dfc17/dfc17d46a8ae602d71c5a553c7e3397e563164d1" alt="Sin título.png Sin título.png"
3) in Linux live we install ssh, because it does not come by default, and we change the default user password that comes by default. In my case it is "Ubuntu".
data:image/s3,"s3://crabby-images/b0cd1/b0cd1f487f05f33ac032476e0c112e0039b894fd" alt="mnocciolino_6-1699293438457.png mnocciolino_6-1699293438457.png"
data:image/s3,"s3://crabby-images/22479/224793c7f5bdf5f53a19bf581212f89f6559e630" alt="mnocciolino_7-1699293450483.png mnocciolino_7-1699293450483.png"
4) Log in via ssh to the live Linux and paste the following commands as root:
Note: This commands are parts of sk92663
sudo su
mkdir /mnt/gaia
mount /dev/vg_splat/lv_current /mnt/gaia
mount /dev/vg_splat/lv_log /mnt/gaia/var/log
mount /dev/sda1 /mnt/gaia/boot
mount --bind /dev /mnt/gaia/dev
mount --bind /proc /mnt/gaia/proc
mount --bind /sys /mnt/gaia/sys
chroot /mnt/gaia /bin/bash
data:image/s3,"s3://crabby-images/b223a/b223a925bc27e1e2ccd3ef1e809eda5cfe001eaa" alt="mnocciolino_8-1699293955128.png mnocciolino_8-1699293955128.png"
5) Set the following command and paste it, the user and IP are from the "Another Linux".
ssh user@<ip address> cat .ssh/id_rsa.pub | tee -a /home/admin/.ssh/authorized_keys
data:image/s3,"s3://crabby-images/7777f/7777ff533a4b13bba0264f96ce1d275f20b15d33" alt="Sin título1.png Sin título1.png"
This command como the content form id_rsa.pub to authorized_keys
6) Reboot Management
data:image/s3,"s3://crabby-images/d5706/d57064645c3a038f68d926875118532229196c70" alt="mnocciolino_9-1699295213754.png mnocciolino_9-1699295213754.png"
7) When it finishes booting, log in via ssh with the admin user, from the "Another Linux" and you should log in without password.
ssh admin@<ip address>
data:image/s3,"s3://crabby-images/6e905/6e905d0972519db8291d3723394f4302d0878eb5" alt="Sin título2.png Sin título2.png"
8) Now we can change admin password from clish.
-----------
Any suggestions or comments are welcome
mnocciolino