Prime Collaboration Assurance 10.6 root ssh login

I am not able to login to PCA 10.6 using root over ssh I believe I have the password correct.  It just fails authentication.  I can ssh to admin fine and I can use the "root" command and then authenticate to the bash shell, but don't seem to have access to all the commands.  Any way to troubleshoot this or a little more insight would be great.

Hi Stephen,
root access to the CLI has been disabled (for security reasons) in Prime Collaboration Assurance 10.6.
This Information can be found here (look for the heading 'General'):
http://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/collaboration/10-6/assurance/advanced/guide/Cisco_Prime_Collaboration_Assurance_Guide_Advanced_10_6/Cisco_Prime_Collaboration_Assurance_Guide_Advanced_10_6_chapter_01.html#concept_8004BC83C1C34B81A6F7C1B270DE453B
There is a hidden page that you can use for viewing logs, etc.:
https://<FQDN or IP-Address of Prime>/emsam/index.html#pageId=com_cisco_emsam_page_diag_links
Best regards
Igor

Similar Messages

  • Cisco Prime Collaboration Assurance _ Web login

    I have recently deployed Cisco Prime Collaboration Assurance standard within our Vmware environment with the view to evaluate and deploy into production.
    I have successfully deployed within the environment and can log into the appliance via SSH via the root, admin and globaladmin account however when I try to login through the Web Gui with the above accounts, i am getting the " invalid username or password" error.
    Can anyone provide guidance please 
    Peter

    Hi Peter,
    Never faced such issue.
    Look into the bugs if helps.
    PC 9.0 After restore from backup, cannot login - invalid password
    CSCui00260
    Description
    Symptom:
    cannot log in to the GUI with any known username/pw including globaladmin account.
    tomcat logs will show 'untrusted certificate' errors.
    Conditions:
    seen after a fresh restore from backup on a new server.
    Workaround:
    contact BU for workaround.
    Assurance password for globaladmin with * at end or beginning fails
    CSCue81630
    Description
    Symptom:
    User 'globaladmin' is unable to login to Prime Collaboration Assurance
    Conditions:
    The password for 'globaladmin' contains '*' at the beginning or end of the password
    Workaround:
    Do not use '*' character at the beginning or end of the password
    regds,
    aman

  • Cisco Prime Collaboration Assurance Standard

    Hi All,
    We have recently deployed Cisco Prime Collaboration Assurance Standard Server. The issue that I am facing is that after some time the server collapses and logs me out, even though I can connect via the cli.
    The version of prime we are using is : 10.5.1.53684.
    I am attaching some logs that I got from the cli mostly related to apache.
    Has someone faced this issue?
    Thanks
    Hassan

    Hi Aman,
    Thank you I will have a look at the bug. I was following the troubleshooting document and as compared to that document the service running when I do a sh application status cpcm are a lot less.
    http://docwiki.cisco.com/wiki/Troubleshooting_Cisco_Prime_Collaboration#How_to_verify_the_Cisco_Prime_Collaboration_Assurance_installation_.28for_advanced_and_standard_modes.29.3F
    STAT   PID USER     COMMAND             ELAPSED
    ===============================================
    SNl   1119 root     emsam_perfmonen       12:50
    S<l   1288 root     emsam_tomcat          12:39
    SNl   1400 root     emsam_poller          12:16
    SNl   1625 root     emsam_fault           11:56
    S<l  32045 root     Decap_main            14:41
    SN   32164 postgres postgres              14:40
    SN   32274 primea   postmaster            14:29
    SNl  32317 root     emsam_mq              14:12
    SNl  32380 root     cpc_multiproclo       14:04
    SNl  32414 root     emsam_inventory       14:04
    Regards
    Hassan

  • Cisco Prime Collaboration Assurance IPPhone 3901 no serial number report

    Hi All,
    I have installed Cisco Prime Collaboration Assurance in my office and try to create phone inventory report , so far no problem , but when i add IPPhone 3901 there no serial number in the report , I have enable web access on the phone , i can see the serial number by click the IP  .
    any help ?
    Best Regards,
    Tommy

  • Prime Collaboration Assurance custom dashboard?

    Hi Everybody, 
    I'm new to Prime Collaboration... here are the questions
    Now I am using PCA 10.0 (assurance) and CUCM 10.5, and using UC Performance Monitor to see some stat ... 
    1.
    when using the "Cisco CallManager - CallsAttempted", when will the CallAttempted value will be resetted to Zero? and can it be done manuelly?
    2. 
    when I custom a dashboard "Cisco CallManager - CallsInProgress" , and make a test call. The value is zero continuiously 
    ("CallsActive", "RegisteredHardwarePhones" are not working too. but the "CallsAttempted" and "CallsCompleted" show correctly)
    However, when I switch to PCA's default dashboard "Call Activity", it shows the value correctly in "Calls In Progress".
    Why the same "CallsInProgress" but in different result?
    Thanks in advance 
    Sam

    Hi gokgokgok,
    I did find a solution.
    Here is what I did:
    1) Deleted the CUCM from Prime Collaboration Assurance 10.6.
    2) Changed the cluster ID from the default value StandAloneCluster to a unique value (e.g. LabCluster) on CUCM.
    3) Restarted the services 'Cisco CallManager' (Please note: a call processing service interruption could occur) and 'RIS Data Collector'.
    4) Discovered the CUCM in Prime Collaboration Assurance 10.6.
    The above steps are also described here:
    http://www.cisco.com/c/en/us/products/collateral/cloud-systems-management/prime-unified-operations-manager/deployment_guide_c07-629357.html#wp9000663 (Cluster ID of a Cisco Unified Communications Manager Cluster ).
    If the above steps do not help, then the only way to fix the issue is to do step 2 and 3, then reinstall Prime Collaboration Assurance and then discover the CUCM.
    Best regards
    Igor

  • Change from MSP to Enterprise mode in Prime Collaboration Assurance 10.5

    Hi all,
    I googled a lot but I didn't find anything about it.
    Is it possible to change from MSP mode to Enterprise mode without the need to reinstall the OVA template again?
    Thanks a lot.
    Luigi

    Hi,
    Check this info :
    Virtual Machine Requirements for Prime Collaboration Assurance
    You must review the Installation Modes and Requirements section to understand the supported installation deployment modes and applications during the Prime Collaboration installation.
    The following table lists the virtual machine requirements for Prime Collaboration Assurance application, based on the number of endpoints managed in Prime Collaboration. The virtual machine requirements mentioned in this table is also applicable for Prime Collaboration Analytics and Prime Collaboration Contact Center Assurance. For details on the endpoint quantities supported in each OVA deployment model, see Endpoints and Contact Center Agents Count.
    There are no separate Prime Collaboration Assurance OVAs for Enterprise and MSP deployments for Small, Medium, and Large deployment models. During the installation select the appropriate options to deploy the required applications; by default, the Prime Collaboration Analytics is installed as part of the Prime Collaboration Assurance - Advanced Enterprise installation.
    For Very large deployment model, there are separate OVAs for Enterprise and MSP. During the installation of the Prime Collaboration Assurance - Advanced Enterprise deployment, you can choose whether to deploy Prime Collaboration Analytics or not.
    The Prime Collaboration Analytics application is not supported in the MSP deployment.
    http://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/collaboration/10-5/upg_mig/guide/Cisco_Prime_Collaboration_Upgrade_and_Migration_Guide_10_5/Cisco_Prime_Collaboration_Upgrade_and_Migration_Guide_10_5_chapter_0101.html
    regds,
    aman

  • Cisco Prime Collaboration Assurance - INACCESSIBLE

    Hi,
    I setup a testing Cisco Prime Collaboration Assurance (CPCA) with Advanced version, which connected with two CM clusters both is the 10.5 version.
    The result is one CM cluster can be monitored, but the second CM cluster cannot be monitored. The fail CM showed the Discover Device on CPCA as the below error: (Showed one of EX90 cannot be accessed, then all devices cannot be monitored?)
    One CM success: (CM1 assurance domain)
    Second CM fail: (CM2 assurance domain)
    Any idea on that?

    Hi,
    Just a guess:
    check for snmp ports being blocked for this cluster across firewall.
    regds,
    aman

  • Cisco Prime Collaboration Assurance

    Hello Guys,
    I'm tryng to implement a Cisco Prime Collaboration Assurance on a costumer, but it does not create the phones inventory.
    The UC Cluster nodes are already managed.
    I've followed some Cisco Guides to set this up, and it is not working.
    http://www.cisco.com/c/en/us/products/collateral/cloud-systems-management/prime-collaboration/guide-c07-732215.html#_Toc394127247
    http://docwiki.cisco.com/wiki/Setting_up_Devices_for_Prime_Collaboration_Assurance
    http://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/collaboration/10-5/assurance/standard/guide/Cisco_Prime_Collaboration_Assurance_Guide_Standard_10_5.html
    Please, how the PCA discover the Cisco IP Phones and endpoints?
    I'm working with a Prime Collaboration Assurance 10.5 Advanced License. All the UC nodes are on 10.5 version.
    Thanks in advance and best regards.

    Hi Pedro,
    I am fine.
    thanks for the ratings.
    What I could find that this could be again the bug but not sure since I  never came across this issue when worked on PCA 9.x?
    Data sorting issue in Trunk Utilization & Location CAC bandwidth
    CSCur69981
    If TAC case is still opened, you can speak to him about this issue as well.
    there is a similar discussion on E1 channel but could not be resolved.
    https://supportforums.cisco.com/discussion/12297036/cpc-assurance-not-showing-e1-cas-channel-status
    regds,
    aman

  • Prime Collaboration Assurance - Configure SNMP Community on Appliance Itself

    Dear forum users.
    Very simple question, I need to configure an SNMP Read-Only community on the two Prime Collaboration appliances themselves.The client has a 3rd party monitoring tool they want to use to query the Prime appliances themselves. I have searched through the CCO documentation but can't find any reference to it. Part of the problem is that if you search Prime and SNMP you get lots of hits about SNMP on managed devices but not about the actual Prime appliances themselves. 
    I reckon you could do it because we have root CLI access but I don't want to do anything that is not supported by TAC. My client operates in a very sensitive environment. 
    Any help much appreciated. 

    Hi.
    You don't need root access for that. Login as admin, and issue the following:
    conf t                                                          --> like you would do on an IOS-based device
    snmp-server community public ro
    snmp-server contact Phil
    snmp-server location CiscoILM
    exit
    write memory
    If you don't run the last, your changes will be rolled back at next reboot (again like on an IOS box).
    This works on PCAA 10.5.1 (didn't try the previous releases) and allows MIB II access to PCAA.
    Note that PCAA does not send traps (so don't look for the snmp-server enable traps command). PCAA 10.6 will be able to raise an alarm in case of CDR collection max supported rate exceeded that can then be notified to an external manager via the standard event notification mechanism, but that's the only one that will be supported.
    HTH
    /Phil

  • Cisco Prime Collaboration Assurance 10.0 | CDR Issues

    Hello,
    I'm trying to configure my CUCM 10.0 to send CDR record to my Cisco Prime Collaboration 10.0, but the CUCM can't connect to the SFTP in the Cisco Prime.
    I tried connect to other SFTP client, but unsuccessful, too. I have received "invalid username or password" response.
    I can connect the port 22 and 26, by command prompt for example. I followed all the steps of the "Deployment Guide", but I can't add the Cisco Prime in CUCM.
    Thanks a lot
    Eduardo Lassance

    Hi Edu,
    In Prime Assurance , under Adminstration ---system setp ---assurance setup ---sftp settings , in username [smuser] , can u re-enter the password , apply and then, check.
    regds,
    aman

  • Is adding a Billing Server mandatory to view call quality graphs in Prime Collaboration Assurance and Analytics 10.5

    Hi,
    we are in the process of demostrating Cisco Prime Collaboration 10.5 Assurance and Analytics and somehow are not able to pull Call Quality Graphs. The question is Is it mandatory to add a Billing Server to get the missing graphs.
    Thanks in advance
    Kunal

    As per the following guide you should be able to discover and manage endpoints that are registered to Cisco TMS and Cisco VCS with both PCA Standard and Advanced.
    http://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/collaboration/10-5/assurance/standard/guide/Cisco_Prime_Collaboration_Assurance_Guide_Standard_10_5/bk_assurance_standard_chapter_010.html
    HTH
    Manish

  • Cisco Prime Collaboration Assurance SNMP authentication

    Hello
    i see in Cisco Prime Collaboration the following minor alarms:
    Description=SNMP entity has received a protocol message that is not properly authenticated
    2014-10-16 13:37:09    Local7.Critical    62.25.80.199    Oct 16 13:37:06 HCCPCA3A CPCMHCCPCA3A:%local7-2-ALARM: 14$Description=SNMP entity has received a protocol message that is not properly authenticated.::Status=1,active^Severity=minor^Acknowledged=no^AlarmURL=https://62.25.80.199/emsam/index.html#pageId=com_cisco_ifm_web_page_alarms&queryParams=Id%3D31755519&forceLoad=true^Associated Events=https://62.25.80.199/emsam/index.html#pageId=com_cisco_ifm_web_page_alarms&queryParams=alarmId%3D31755519&tView=events^Device Work Center=https://62.25.80.199/emsam/index.html#pageId=com_cisco_emsam_page_inventory&deviceId=3827396^CUSTOMER=CUSLAB08^Private IP Address=172.29.15.5^Default Alarm Name=MinorAlarm^Managed Object=172.29.15.5^Managed Object Type=Contact Center Enterprise^MODE=2;Alarm ID=31755519^Component=172.29.15.5<000><000>
    i know i can suppress the alarms, but can anyone tell me why this is generated?  how is it when Cisco PCA can manage the device, i get authentication issue on SNMP v2c ?
    thanks in advance

    Hi Phil,
    Even I am facing this issue.
    The server is in managed state in Device Work Center. But still observing the Alarm " SNMP  entity has received a protocol message that is not properly authenticated.".
    Also it takes 15 to 20 minutes for an alarm to get cleared. 
    Thanks,
    Dinesh

  • Cisco Sensor 1040 and Cisco Prime Collaboration Assurance 9.0

    Hey Guys,
    We have setup Cisco Prime CA and trying to hook a Sensor onto it. The sensor is searching for a few.cnf files over tftp. Where can i find these files ?
    PS: if this is the wrong place please tell me where to post this.
    Thanks
    Varadarajan.R

    Hello Varda,
    It seems as the 1040 sensors are not finding the TFTP server. The TFTP server list should not contain the ipaddress with values 32 or 92 in their octets,
    1. The 1040 needs to learn of the TFTP by DHCP option 150.
    2. Please make sure that it is set on your DHCP server. 
    3. To confirm that the 1040 sensor is receiving the TFTP IP open a web browser and type http://  and see if the TFTP address field is showing the IP. 
    4. If it is then you might also need to restart the TFTP service on the CUCM so that the 1040 can download the cnf and image files.
    Attached is the userguide for 1040. Go through it and this should be able to resolve your issue.
    This is a other  method to check the  sensor  is fine
    Fist step install  download winagents tftp server ,
    enter a Service Monitor Server   Configuration / sensor1040 and in TFTP server  enter    ip address(winagents tftpserver) and go to SETUP
    in setup   put you ip address in PRIMARY SERVICE MONITOR  and push OK   you look the server write file in (TFTP server )
    Next STEP
    Go to MANAGEMENT   and  add new sensor you need mac address remember second port in sensor is span port you can make a sencond file in the tftp server
    Next STEP
    go to service monitor server and copy  file *.img CSCOpx/
    Next STEP
    Search  you dhcp server switch     option 150 in put your ip address tftp server when sensor power off  and power on the sensor search tftp server and search files to autoconfig and register to service monitor when test is ok
    its time to upload change winagent tftp server to  callmanager tftp server
    Hope this helps
    Thanks & Regards,
    Venkitesh

  • Prime Collaboration Version: 9.0.24376 CLI root/admin Password Recovery

    Dear forum users.
    My client needs to recover both the CLI admin and root passwords for their PCA and PCP VM appliances, Version: 9.0.24376, don't ask why!
    Is the attached document the correct method to do this?

    Hi,
    I have captured from the link which says:
    http://www.cisco.com/c/en/us/td/docs/net_mgmt/prime/collaboration/9-0/administration/guide/PC9-0AdminGuide/usermanagement.html
    We recommend that you write down the root password as it cannot be retrieved
    Resetting Prime Collaboration Assurance Passwords
    As a super administrator, system administrator or network operator, you can reset the password for other
    Prime Collaboration users.
    You can reset the Prime Collaboration Assurance web client globaladmin password using the following
    procedure.
    To reset the Prime Collaboration Assurance globaladmin password:
    Step 1
    Log in as a root user.
    Step 2
    Enter the "goemsam" command:
    Step 3
    Execute the following:
    su admin
    conf t
    username
    username password {hash|plain|remote} password role {admin|user}
    regds,
    aman

  • VCS registered endpoints not displayed in Cisco Prime Collaboration 10.5 Assurance and Analytics

    Hi,
    We have been able to successfully add VCS in Prime Collaboration Assurance and Analytics 10.5 however the endpoints registered with VCS are not displayed in the list of devices. Though, we have been able to add a video codec manually which originally is registered with VCS.
    Thanks in advance
    Kunal

    Hi F,
    After investigation this issue, we came to know that this is due to the use of 4096 bit ssl certificate by the VCS.
    This is currently not supported by Prime Collaboration 10.5.1 and will be fixed in release 10.6 (available beginning of December).
    In the mean time you will be able to discover the VCS is you change the default VCS certificate to match the types that are supported by Prime Collaboration.
    Regards,
    Kunal

Maybe you are looking for