Description
It is necessary to change service account passwords from time to time.
In addition to changing the password in Active Directory, there are several steps that must be completed to change the account password within the Winshuttle system.
Applies To
Workflow, Central Server
Solution
1. Steps to do Before Password Change in Active Directory
Workflow:
SharePoint Impersonation Account
Setting the password in Workflow Administration
-
Open Winshuttle Workflow Central Administration
-
Under “Server Administration” Click “Configure Options”
-
In the “Name Contains” field type “Impersonation” and click “Search”
-
Click on “SharePointImpersonationPassword”
-
Click the “edit” icon to the right of the password value field
-
Delete the contents
-
Paste your password into the field
-
Click Save next to the value field
-
Click Save under the Property
Database Impersonation Account
Setting the password in Workflow Administration
-
Open Winshuttle Workflow Central Administration
-
Change the URL ending to :54073/farmconfiguration
-
Click the “edit” icon to the right of the password value field on “DatabaseImpersonationPassword”
-
Delete the contents
-
Paste your password into the field
-
Click Add next to the value field
2. Steps to do in case Password for Winshuttle service account has been Changed in Active Directory
Passwords for Central:
Update “Account Preference – Query Output to SharePoint List”
-
Open Winshuttle Central Administration
-
Query column click “Preferences”
-
If “System Account” is checked, and is using an account that has a changed password, update the password and click save.
Winshuttle Server
Update IIS:
-
Open IIS
-
Go to Application Pools
-
Expand the Identity Column
-
For each App Pool running under an account who’s password has changed do the following:
-
Right-click
-
Advanced Settings
-
Click on “Identity”
-
Click on the ellipsis
-
Leave “Custom Account” checked and click “Set” button
-
Fill in domain\username in the “User Name” field
-
Fill in the new password for both Password fields
-
-
After all app pools have been updated do an IISReset
Update Services.msc:
-
Open Services.msc
-
Sort by “log on As”
-
For every service that is running under a service account that has a new password:
-
Right-click the service (WinshuttleWorker)
-
Click Properties
-
Go to the Log On tab
-
Update the Password fields with the new password
-
Click Apply
-
Click Ok on the Pop-Up
-
Go to the General Tab
-
Click the Stop button and wait for the service to stop
-
Click the Start button and wait for the service to start
-
Click OK
-
Workflow:
SharePoint Impersonation Account
Encrypting the Password
-
Open Winshuttle Workflow Central Administration
-
Under “Server Administration” click on “Admin Commands”
-
Under “Configuration” click on “Encrypt Config Values”
-
In the “Configuration Name” text box type
SharePointImpersonationPassword
Note: This field is case sensitive
-
Click the checkbox for “Use Config Value”
-
Click “Continue”
Database Impersonation Account
Encrypting the Password
-
Open Winshuttle Workflow Central Administration
-
Under “Server Administration” click on “Admin Commands”
-
Under “Configuration” click on “Encrypt Config Values”
-
In the “Configuration Name” text box type
DatabaseImpersonationPassword
Note: This field is case sensitive
-
Click the checkbox for “Use Config Value”
-
Click “Continue”
Final Steps and Verification
Final Steps
-
Open an elevated CMD prompt
-
Execute and IISReset
Verification
SharePoint Impersonation Account
-
Open Winshuttle Workflow Central Administration
-
Under “Server Administration” Click “Configure Options”
-
In the “Name Contains” field type “Impersonation” and click “Search”
-
Click on “SharePointImpersonationPassword”
-
Ensure the password is now encrypted
-
Click Cancel
-
Database Impersonation Account
-
Open Winshuttle Workflow Central Administration
-
Change the URL ending to :54073/farmconfiguration
-
Ensure the password is now encrypted
-
Click Cancel
-
- Note:- Please check if the workflow admin account(for which you have updated the password) is same under application pool and shoule be maintained under site collection administrators.
If a user gets below message after making all the relevant changes ; please check the below steps.
1) First thing, you would need to login with farm admin account on workflow site and then make the requested changes.
2) Secondly, you would need to check the dropdown if you are able to see the share point site or not
3) You would need to update the app pool password as well manually and do an iisreset
Changes in Task Scheduler
In The task scheduler you can change it by finding the service ; Right click on Properties and then check what user name and password is user there and change accordingly.
Password reset in load balancer(if any)
Please check the document for the process to reset password in load balancer.
Comments
0 comments
Please sign in to leave a comment.