OSGi Web Console Password | Community
Skip to main content
ClintLundmark
Level 3
May 26, 2020
Solved

OSGi Web Console Password

  • May 26, 2020
  • 2 replies
  • 1664 views

I am doing a security review of our AEM instance and going through the Security Checklist.   It is not clear to me what "Changing the OSGi Web Console Password" actually does.  I changed the AEM admin user password to "rainyday".  I changed the OSGi Web Console password to something distinct per the instructions - "sunnyday".  To get to the OSGi Web Console the AEM admin user password "rainyday" allows access NOT the password set for OSGi Web Console. 

  1. Why is is recommended to set an OSGi Web Console password?
  2. When is the password used?
  3. What is the consequence of not setting the OSGi Web Console password?
  4. What is the consequence of setting them to the same thing? "rainyday".

...

clint

This post is no longer active and is closed to new replies. Need help? Start a new post to ask your question.
Best answer by Nikhil-Kumar

@clintlundmark 

As mentioned in the docs under security checks.
We usually update the admin credentials to secure the crx and system/console(OSGI Web Console) as it has all the confidential information on code and jars.
So once you update the admin password let's suppose to sunnyday then in that case using the same password you can login to crx as well as OSGI web console.

Thanks,
Nikhil

2 replies

ClintLundmark
Level 3
June 9, 2020

Somewhat as a follow up to my original set of questions...

 

How do I test the OSGI Password?  If I set it to something like "sunnyday" how do I know it was actually set or set to what I think it is?

 

Any help to better understand this is appreciated!

 

Thanks.

..

clint

kautuk_sahni
Community Manager
Community Manager
August 25, 2020
Request you to create a separate Questions for follow up Qs. It helps in SEO.
Kautuk Sahni
Nikhil-Kumar
Community Advisor
Nikhil-KumarCommunity AdvisorAccepted solution
Community Advisor
August 24, 2020

@clintlundmark 

As mentioned in the docs under security checks.
We usually update the admin credentials to secure the crx and system/console(OSGI Web Console) as it has all the confidential information on code and jars.
So once you update the admin password let's suppose to sunnyday then in that case using the same password you can login to crx as well as OSGI web console.

Thanks,
Nikhil