sk182185 - Gaia OS contains a built-in user called 'cp_ender'

Gaia OS contains a built-in user called 'cp_ender'

Solution ID: sk182185
Technical Level: Basic
Product: Maestro HyperScale Firewall, Multi-Domain Security Management, Scalable Chassis, Security Gateways, Security Management
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Last Modified: 2024-10-22

Symptoms

Cause

The pre-defined user "cp_ender" was used for Gaia REST API in older versions.

An upgrade does not remove this user.

In versions R80.40 and higher, this user cannot log in (it does not have a password) and it does not have any permissions in Gaia OS. This user cannot and does not do anything.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

If you choose not to upgrade, remove the "cp_ender" user:

  1. Connect to the command line on the Gaia OS server with an SSH client.

  2. Log in to the Expert mode.

  3. Check if this script exists:

    ls -l /rest_api/scripts/generate_local_user.sh

If the script exists, then run it with this syntax to remove this user:

/rest_api/scripts/generate_local_user.sh -u

  1. If the script does not exist, then run these commands:
    1. Start the CLI session recording:

      script /var/log/Remove_User_cp_ender_sk182185.txt

      This file will contain the entire CLI session - the commands you enter and their outputs.

      For more information, see https://linux.die.net/man/1/script.

    2. Select all these commands, copy them, and paste them in the SSH client:

| | | --- | | dbset passwd:cp_ender
dbset passwd:cp_ender:shell
dbset passwd:cp_ender:realname
dbset passwd:cp_ender:passwd
dbset passwd:cp_ender:homedir
dbset passwd:cp_ender:gid
dbset passwd:cp_ender:uid
dbset mrma:users:user:cp_ender
dbset mrma:users:user:cp_ender:role:adminRole
dbset mrma:users:user:cp_ender:role:adminRole:domainname:default
dbset mrma:users:user:cp_ender:access_mechanism:CLI
dbset mrma:users:user:cp_ender:access_mechanism:Web
dbset :save
rm -rf /home/enderUser/ |

  1. Stop the CLI session recording:

    exit

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2024-04-07
Last Modified: 2024-10-22