Issue:
Due to security requirements HTTP and HTTPS are deactivated by default on NetBotz 4.7.
Product Line:
NetBotz v3 Wall Appliance: 355/356 (NBWL0355/6) & 455/456 (NBWL0455/6)
NetBotz v3 Rack Appliance: 450/451 (NBRK0450/1), 550 (NBRK0550), & 570 (NBRK0570)
Environment:
NetBotz v3 (4.7 and higher)
Cause:
With the introduction of new California State legislation (SB-327), which came into effect January 1st, 2020, any manufacturer of a device that connects “directly or indirectly” to the internet must equip it with “reasonable” security features, designed to prevent unauthorized access, modification, or information dis-closure. APC by Schneider Electric (APC) network-enabled devices firmware is updating in compliance with this legislation. Please note that the NetBotz can still get a DHCP address but without first logging in serially, you can not add it to Data Center Expert or log in through the web.
Resolution:
The following are the overview of changes which will come into effect with this new Botzware 4.7.0 version. Please note that this applies on a newly deployed or newly reset to default appliance. These changes are not going to affect a unit that is currently configured and is simply being upgraded to 4.7
WEB access will be OFF by default. It will be required to login via the USB console (serial session) using root/apc and define a new password.
You will then be able to login using a web browser via HTTPS (https://Netbotz_IP) with the following credentials:
Username: apc
Password: defined during initial console configuration
Note: The serial config utility no longer works with v4.7 and higher. This is due to the fact that it can not process the new password requirement.
The new password update will look similar to the below listing:
Warning: system login through this interface without direction
from NetBotz Support will void your warranty.
netbotzDD3A7B login: root
Password:
Linux (none) 2.6.12 #307 Tue Jul 9 12:11:47 EDT 2019 ppc unknown
Welcome to NetBotz BotzWare V4.7.0
***************************************************************************
* To increase security, initial access to new NetBotz appliances has been *
* limited to this command console. *
* Once the Root password is set here, you can access the WEB UI and *
* use Advanced View and Data Center Expert to configure the appliance. *
* Only HTTPS (TCP port 443) will be activated at that time *
***************************************************************************
New password:
Retype new password: