Device Credential Management

Overview

HPE Morpheus Software provides centralized credential management for infrastructure devices such as iLO (Integrated Lights-Out), ESXi hosts, and network switches. Credentials are securely stored in the Cypher secrets engine rather than in plaintext database fields, enabling secure rotation and auditing of device access credentials.

Device credentials can be linked to one or more infrastructure objects (compute servers, network servers, or storage servers) and are managed from the Infrastructure Credentials interface.

Role Requirements

  • Infrastructure: Compute role permission at Full level is required to create, edit, or delete credentials.

Viewing Credentials

Navigate to |InfCre| to view all stored device credentials. The list displays:

Column

Description

Name

Descriptive name for the credential

Type

Credential type (e.g., Username/Password)

Status

Current status: OK, Warning (partial failure), or Error

Linked Devices

Number of devices using this credential

Creating a Credential

  1. Navigate to |InfCre|

  2. Click + Add

  3. Select the credential store (integration) for secret storage

  4. Complete the credential form:

    Field

    Description

    Name

    A descriptive name for the credential

    Credential Type

    Select the type of credential (e.g., Username and Password)

    Username

    The device username (e.g., Administrator, root)

    Password

    The device password

  5. Click Save

The credential is encrypted and stored in the Cypher secrets engine.

Linking Credentials to Devices

Credentials can be linked to infrastructure devices during server creation or by editing an existing server:

  1. Navigate to the server detail page or create a new server

  2. In the Credentials section, select a stored credential from the dropdown

  3. Save the configuration

A single credential can be linked to multiple devices. When the credential is updated, all linked devices will use the new value on their next connection.

Note

When a credential store is configured with localCredentials: false, inline password entry is disabled and users must select a stored credential.

Editing a Credential

  1. Navigate to |InfCre|

  2. Click the credential name or select Edit from the actions menu

  3. Update the username, password, or other fields as needed

  4. Click Save

All devices linked to the updated credential will use the new values on their next connection.

Deleting a Credential

  1. Navigate to |InfCre|

  2. Select Delete from the actions menu

  3. Confirm deletion

Warning

Deleting a credential removes all device links. Devices that relied on this credential will no longer have stored access credentials until a new credential is linked.

Credential Status

Status

Description

OK

Credential is healthy and accessible

Warning

Some linked devices experienced issues (partial failure)

Error

Credential access failed for all linked devices

A background job (CypherBackedCredentialSyncRetryBackgroundJob) automatically retries failed credential operations for devices that were unreachable during the last update.