Resetting platform credentials

Occasionally a situation will arise where you have a functional JACE-8000 controller but no valid credentials or system passphrase. This could be due to a change in building ownership or control contractors.  In Niagara 4.4 and later, the Platform Account Recovery feature provides you with a secure method of regaining access to the JACE-8000 without losing station data and configuration.
Prerequisites:
  • A USB-to-micro USB cable (same cable as that used to connect a smart phone to a computer) connects the controller to your PC.
  • A terminal emulator (system shell) program, such as PuTTY, is installed on your PC.
  • During the procedure, you will be prompted to provide the hostid and “proof of ownership” for this controller.

Resetting platform credentials is accomplished via a multi-stage process that involves using serial shell software plus contacting your Support channel, and interacting with Tridium in order to initiate a secure method of validating that you (the serial shell user) are authorized to reset the platform credentials and system passphrase.

 
NOTE: The controller must be powered off to initiate this procedure. Additionally, you must be able to communicate with Tridium via phone or email. Also, this process could conceivably take several hours to complete, depending on your access to cell phone or internet service.
 

Perform the following steps:
  1. Power off the controller.
  2. Using the serial shell program on your PC, open a serial connection to the controller.
  3. Power up the controller and during the boot sequence, press ESC to enter the recovery mode which presents alternate boot options.
  4. While viewing the Alternate Boot Options menu in the serial shell window, enter 8 to select the option to “Reset Platform Credentials”, and when prompted to confirm that you intend to reset platform credentials and system passphrase, enter Y to continue.
    The Platform Access Recovery screen displays the controller’s hostId, and OS version, as well as a randomly generated token and additional instructions, as shown.
    Image
  5. Contact your appropriate Support channel and request credential/system passphrase reset for the hostid shown on-screen.
  6. When prompted, provide the support representative with the required “proof of ownership” for the controller.
    Once proof of ownership is established the support representative will notify Tridium.
  7. When prompted In the Platform Access Recovery screen, enter the customer name. For example, Joe NewBuildingOwner.
  8. Contact Tridium (either via phone or email) and provide the generated token, the hostid and the customer name entered in the previous step.

    The Tridium representative validates your customer identity via Niagara Licensing, and generates a “Signature” for the token/hostid/customer name that includes a Reset Authorization Key. This Signature is sent to you either by phone or email.

     
    CAUTION: The Reset Authorization Key is valid only for 24-hours from the time it is generated. If you do not enter the key in the Platform Access Recovery screen within the 24-hour period, you must start over with step 1 of this procedure to obtain another Key.
     
  9. Once you have received the Signature, in the Platform Access Recovery screen indicate your preference for entering the Reset Authorization Key in the serial shell window, enter one of the following:
    • Enter1 for Single Line (best when the Key is copied from email), and at the “Enter Key” prompt paste the Reset Authorization Key. After checking the key enter v to verify it (or if necessary, enter 1 to edit the key and then v to verify it.)
      Image
    • Enter2 for Multiple Line (best when receiving the Key over voice), and at the “Enter line x” prompts enter the string of characters as instructed. After checking your entries enter v to verify the key.
      Image
    The controller uses the previously installed tridium certificate to verify that this Signature was generated by private key for the given token/hostid/customer name values. Afterwards, the system software generates the factory default username/password credentials and default system passphrase.

    The serial shell window displays the following text and reboots after the specified amount of time:

    Verification Passed
    
    System user credentials are reset
    Shutdown in 10 seconds

  10. Make a serial or platform connection to the controller. On detecting default credentials, the system prompts you to change the default credentials and default system passphrase before completing the platform connection.
On completion, you can login and access the station data and configuration as you normally would.