All Products
Search
Document Center

Bastionhost:Password change task

Last Updated:Jun 20, 2026

Bastionhost provides the automatic password change feature. The feature can periodically rotate passwords or keys of host accounts or rotate passwords or keys of host accounts at a scheduled time based on the password or key rules that you configure. This effectively improves the security of your business. This topic describes how to use the automatic password change feature.

Background information

Multi-Level Protection Scheme (MLPS) requires that the logon credentials, such as passwords and keys, of host accounts be changed on a regular basis. If the passwords or keys are not changed for a long period of time, security risks may arise. However, regular and manual password or key rotation is inefficient and is prone to errors. To resolve this issue, Bastionhost provides the automatic password change feature. This improves the O&M efficiency and ensures security.

Limits

  • Editions: This feature is available only in Bastionhost Enterprise and SM Edition. For more information about how to purchase or upgrade an instance, see Purchase a bastion host and Upgrade a bastion host.

  • Limits on password change tasks:

    • The password change tasks do not support the rotation of shared keys.

    • A host account can be associated with only one password change task.

Prerequisites

Hosts are imported to a bastion host and a host account is hosted in the console of a bastion host. For more information, see Add hosts and Manage a host account.

Create a password change task

  1. Log on to the Bastionhost system. For more information, see Log on to the system.

  2. In the navigation pane on the left, choose Assets > Password Change.

  3. On the Password Change page, click Create Password Change Task.

  4. In the Password Change panel, configure the following parameters and click Create.

    Parameter

    Description

    Task Name

    The name of the password change task.

    Task Type

    Valid values: Key Rotation and Password Rotation.

    Execution Method

    The execution method of the password change task. Valid values:

    • Periodic: Bastionhost automatically runs the task based on the specified execution time and interval.

      • You must set Executed At to a point in time that is at least 5 minutes later than the current time.

      • The maximum value of Period is 365.

    • Scheduled: Bastionhost automatically runs the task at the specified execution time. The execution time must be at least five minutes from the current time.

    Password Rules

    If you set Task Type to Password Rotation, you can configure the password strength and length.

    • Password Strength: You can select character types such as digits, lowercase letters, uppercase letters, and special characters. Bastionhost generates a new password based on your selections. We recommend that you select at least two character types.

    • Password Length: Set a minimum and maximum password length, from 8 to 32 characters. Bastionhost will generate a password of a random length within your specified range.

    • Password Policies: Set the minimum number of required characters, character repetition limits, and excluded characters. The sum of the minimums for all character types cannot exceed the minimum password length.

      • Valid values for the minimum numbers of digits, lowercase letters, uppercase letters, and other characters that the new password must contain: 0 to 32.

      • Valid values for the maximum number of times a character can appear in the new password: 1 to 32.

      • A set of characters that the new password cannot contain.

    Key Rule

    If you set Task Type to Key Rotation, you can configure the key algorithm, key length, and encryption password.

    • Encryption Algorithm: Supported algorithms are RSA and ED25519.

    • Key Length: If you select RSA as the key algorithm, you can set the key length to 2048, 3072, or 4096 bits.

    • Encryption Password: Set the password for key encryption.

    Remarks

    The remarks of the password change task.

  5. Click Associate Account. On the Managed Accounts tab, click Add Host Account.

  6. In the Add Host Account dialog box, select the host accounts and click Add.

    After the accounts are added successfully, you will receive a message that the The password change task is associated with host accounts.. You can view the created password change tasks on the Password Change page.

    Note
    • A host account can be associated with only one password change task.

    • If the task type is Password Rotation, you can only add accounts with managed passwords. If the task type is Key Rotation, you can only add accounts with managed SSH private keys. Rotating a Shared Key is not supported.

Related operations

Immediately run a password change task

After you create a password change task, it runs automatically based on the schedule you set. To run a task immediately, go to the Password Change page, select the task, and click Execute Now at the bottom of the list.

Note
  • If you select more than one password change task, Bastionhost runs the tasks one by one.

  • If the time when you immediately run a periodic or scheduled password change task overlaps with the execution time that you specify for the task, Bastionhost runs the password change task only once. If the time when you immediately run a periodic or scheduled password change task does not overlap with the execution time that you specify for the task, the execution time or cycle that you specify for the password change task is not affected. In this case, although the password is changed after you immediately run the task, the task is still run to change the password based on the specified execution time or cycle.

Change password now

On the Password Change page, click the name of a task. On the Managed Accounts tab, select one or more host accounts, and then click Immediately change the password.

View password change records

  • In the Password Change list, click the name of a completed password change task. On the Managed Accounts tab of the password change task panel, you can view the status by clicking the name of the Status.

    After a task is successfully executed, the Status column shows Modified successfully.

  • The Password Change Records panel displays detailed information about the task execution.

    The details include Executed At, Execution Method (such as Manual), Execution Result (such as Successful), and the Password Change Record (a shell execution log showing the complete command output for the SSH connection and password modification).

Modify, enable, stop, or delete a password change task

After you create a password change task, you can modify, enable, stop, or delete it from the Password Change page.

  • Modify: You can modify the basic information and associated accounts of a task.

    • On the Password Change page, click the name of the task you want to modify. On the Task Details tab, modify the task's basic information and click Update.

    • If you need to modify the managed account, click the Managed Accounts tab. On the Managed Accounts tab, you can add or remove host accounts.

  • Stop: If you do not need a task to run for a period of time, you can stop it.

    On the Password Change page, select the task you want to stop and click Stop. The task status changes to Canceled.

  • Enable: You can restart a stopped task.

    On the Password Change page, select the stopped task you want to enable and click Enable. The task status changes to Pending Execution, and it will resume its automatic schedule.

  • Delete: If you no longer need a task, you can permanently delete it.

    On the Password Change page, select the task you want to delete, click Delete, and then click Delete again in the confirmation dialog box.

    Warning

    After the password change task is deleted, the task cannot be recovered. Proceed with caution.

Export passwords and logs

After a password change task is successfully executed, you can export the new passwords and password change logs.

  1. On the Password Change page, click the name of an executed task. On the Password Change History tab in the task panel, click Export Password.

  2. In the Export Password Change History dialog box, enter a file encryption password of 4 to 32 characters, and then click Export Password Change History.

    The current password of the host account is exported to a ZIP file and saved to your computer.

    Note

    Keep the file encryption password confidential. The file encryption password is required to decompress the exported file and obtain the current password of the host account.

Supported operating systems

Operating system

Version

Windows

Microsoft Windows

  • Windows 7

  • Windows 8

  • Windows 10

Microsoft Windows Server

  • Windows Server 2008

  • Windows Server 2012R2

  • Windows Server 2016

  • Windows Server 2019

  • Windows Server 2022

Linux

Alibaba Cloud Linux

  • 3.2104 64-bit

  • 2.1903 LTS 64-bit

  • 2.1903 64-bit (Quick Start)

CentOS

  • CentOS 6.10 to CentOS 8.5

  • CentOS Stream 8

  • CentOS Stream 9

Ubuntu

  • Ubuntu 20.04 64-bit

  • Ubuntu 18.04 64-bit

  • Ubuntu 16.04 32-bit

  • Ubuntu 20.04 64-bit (UEFI)

  • Ubuntu 22.04 64-bit

Debian

  • Debian 11.8 64-bit

  • Debian 8.9 64-bit

Open SUSE

  • 15.1 64-bit

  • 15.2 64-bit

  • 42.3 64-bit

SUSE Linux

  • SUSE Linux Enterprise Server 15 SP2 64-bit

  • SUSE Linux Enterprise Server 12 SP5 64-bit

CoreOS

  • 34.20210529.3.0_3

  • 33.20210217.3.0_3

Red Hat Enterprise

  • Linux 7 (64-bit)~Linux 8 (64-bit)