sk182185 - Gaia OS contains a built-in user called 'cp_ender'
Gaia OS contains a built-in user called 'cp_ender'
Solution ID: sk182185
Technical Level: Basic
Product: Maestro HyperScale Firewall, Multi-Domain Security Management, Scalable Chassis, Security Gateways, Security Management
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Last Modified: 2024-10-22
Symptoms
- A built-in user called '
cp_ender' may appear in Gaia OS after an upgrade to a version R80.40 or higher.
Cause
The pre-defined user "cp_ender" was used for Gaia REST API in older versions.
An upgrade does not remove this user.
In versions R80.40 and higher, this user cannot log in (it does not have a password) and it does not have any permissions in Gaia OS. This user cannot and does not do anything.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 70
- Jumbo Hotfix Accumulator for R81.10 starting from Take 152
- Jumbo Hotfix Accumulator for R81 starting from Take 106
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
If you choose not to upgrade, remove the "cp_ender" user:
Connect to the command line on the Gaia OS server with an SSH client.
Log in to the Expert mode.
Check if this script exists:
ls -l /rest_api/scripts/generate_local_user.sh
If the script exists, then run it with this syntax to remove this user:
/rest_api/scripts/generate_local_user.sh -u
- If the script does not exist, then run these commands:
Start the CLI session recording:
script /var/log/Remove_User_cp_ender_sk182185.txtThis file will contain the entire CLI session - the commands you enter and their outputs.
For more information, see https://linux.die.net/man/1/script.
Select all these commands, copy them, and paste them in the SSH client:
| |
| --- |
| dbset passwd:cp_enderdbset passwd:cp_ender:shelldbset passwd:cp_ender:realnamedbset passwd:cp_ender:passwddbset passwd:cp_ender:homedirdbset passwd:cp_ender:giddbset passwd:cp_ender:uiddbset mrma:users:user:cp_enderdbset mrma:users:user:cp_ender:role:adminRoledbset mrma:users:user:cp_ender:role:adminRole:domainname:defaultdbset mrma:users:user:cp_ender:access_mechanism:CLIdbset mrma:users:user:cp_ender:access_mechanism:Webdbset :saverm -rf /home/enderUser/ |
Stop the CLI session recording:
exit
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2024-04-07
Last Modified: 2024-10-22