# Fix vCenter root password expired and VCSA disk full (/storage/log)

Source: https://srvscripts.com/guides/vcenter-root-password-expired/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

Two problems account for a disproportionate share of vCenter outages: the appliance root password quietly expiring after its default 90-day lifetime, and a storage partition (most often `/storage/log` or `/storage/seat`) reaching 100%, which causes services to stop or the vSphere Client to log everyone out. They frequently arrive together, because a full log partition stops the password-expiry warning emails from being sent. This guide applies to VCSA 8.0 U3 and vCenter 9.x, which share the same Photon OS layout.

In short: For an expired root password, open the appliance VM console, press Enter at the login prompt or reach the bash shell through single-user mode if the account is locked, run chage -l root to confirm, set a new password with passwd, and…

**Short answer:** For an expired root password, open the appliance VM console, press Enter at the login prompt or reach the bash shell through single-user mode if the account is locked, run `chage -l root` to confirm, set a new password with `passwd`, and disable or extend the expiry with `chage -M -1 root` or in VAMI » Administration » Password expiration settings. For a full `/storage/log`, log in to the shell, find the largest offenders with `du -sh /storage/log/vmware/* | sort -h`, clear rotated logs and old core dumps, and if the partition is legitimately too small, grow the corresponding VMDK in vCenter and run `/usr/lib/applmgmt/support/scripts/autogrow.sh` to expand it.

## Recover from an expired root password

Symptoms: SSH and VAMI logins fail with “authentication failed” or “password expired”, while the vSphere Client SSO login still works. Log in from the VM console in the vSphere Client or Host Client, because the console allows the password-change prompt that SSH sometimes suppresses:

```
login: root
Password:
You are required to change your password immediately
```

Enter the old password again and a new one. If the console rejects the old password entirely because the account is locked after failed attempts, reboot the appliance, press `e` at the GRUB menu, append `rw init=/bin/bash` to the line beginning with `linux`, boot with F10, then:

```
mount -o remount,rw /
passwd root
chage -M -1 root
umount /
reboot -f
```

vCenter 9 requires the GRUB password (set during deployment) to edit the boot line, so keep it in your secret store.

Once back in, set a sensible expiry policy. In VAMI (https://vcenter:5480) » Administration » Password expiration settings, either disable expiry for root or set the number of days and a valid email address for warnings. From the shell:

```
chage -l root
chage -M 365 -W 14 root
```

## Diagnose a full partition

Log in to the shell (`shell` from the appliance shell if you land in the restricted one) and check every partition:

```
df -h
du -sh /storage/log/vmware/* 2>/dev/null | sort -h | tail -20
du -sh /storage/seat/vpostgres 2>/dev/null
du -sh /storage/core/* 2>/dev/null | sort -h
```

The common offenders in `/storage/log/vmware` are `vpxd`, `vsphere-ui`, `eam`, `analytics` and `lookupsvc`, each accumulating rotated .gz files when logrotate has fallen behind, plus core dumps in `/storage/core` after a service crash. `/storage/seat` grows with tasks, events and statistics retention set too high.

## Free space safely

Remove rotated logs and old core dumps, but do not delete the live log a service has open:

```
find /storage/log/vmware -name "*.gz" -mtime +7 -delete
find /storage/log/vmware -name "*.log.[0-9]*" -mtime +7 -delete
rm -f /storage/core/core.*
journalctl --vacuum-time=7d
df -h /storage/log
```

If a live log file is enormous, truncate it rather than deleting it (`: > /storage/log/vmware/vpxd/vpxd-profiler.log`), because a deleted-but-open file does not return its space until the service restarts. For `/storage/seat`, reduce retention in the vSphere Client » vCenter » Configure » Settings » General » Database (task and event retention, statistics levels), then let the nightly cleanup job reclaim space, or run the SEAT cleanup script from `/usr/lib/vmware-vpx/vpxd/` documented for your build.

Restart affected services afterwards:

```
service-control --stop vsphere-ui vpxd
service-control --start vsphere-ui vpxd
service-control --status --all
```

## Grow the partition

When the partition is simply too small for the environment, shut nothing down: in the vSphere Client edit the appliance VM’s settings, identify the disk backing `/storage/log` (disk 5 on the standard layout; run `lsblk` in the appliance to map device names to mount points), increase its size, then in the appliance shell run:

```
/usr/lib/applmgmt/support/scripts/autogrow.sh
df -h /storage/log
```

The script extends the LVM volume and file system online. Snapshot the VM before resizing, and remove the snapshot afterwards because disks with snapshots cannot be extended.

## Verify

`df -h` should show every partition under 80%, `service-control --status --all` should list all services running, and the vSphere Client should log in without the “503 Service Unavailable” banner. Confirm root login works over SSH and note the new expiry date from `chage -l root`. Consider adding the VAMI health API or an SNMP disk check to your monitoring so the partition never reaches 100% again.

## Common pitfall

Deleting everything under `/storage/log/vmware` with a wildcard, including the directories themselves, stops services from starting because they expect their log directories to exist with the right ownership. Delete files, not directories, and if a service will not start afterwards, recreate its directory owned by the correct service user (check a sibling directory with `ls -ld`).

## VCenter root password expired at a glance

**Official documentation:** [Broadcom TechDocs (VMware)](https://techdocs.broadcom.com/), [Linux man pages](https://man7.org/linux/man-pages/).

**Related guides:** [Fix “The redo log of .vmdk is corrupt” on ESXi and Horizon linked clones](https://srvscripts.com/guides/redo-log-of-vmdk-is-corrupt/) · [DirectAdmin license errors and update failures: da update, IP/hostname mismatches](https://srvscripts.com/guides/directadmin-license-error-update-failures/) · [cPanel 2026 pricing and licensing explained: Solo, Admin, Pro, Premier and WP Squared](https://srvscripts.com/guides/cpanel-pricing-2026-licensing/).

## Frequently asked questions

### Does the root password expiry also affect the administrator@vsphere.local account?

No. The SSO administrator follows the SSO password policy under Administration » Single Sign On » Configuration » Local Accounts, with its own default of 90 days. An expired SSO password shows as a login failure in the vSphere Client rather than at the appliance shell.

### How long does the autogrow script take to extend a partition?

Usually under a minute; the LVM extend and file system resize happen online with no service restart. The disk resize in the vSphere Client is instant, but it is refused if the appliance has a snapshot.

### Can I undo a log cleanup or partition expansion?

Deleted rotated logs are gone, though the support bundle history is rarely needed beyond a week. A partition expansion cannot be shrunk again; the only reverse path is restoring the appliance from a file-based backup onto a fresh deployment.
