NetLock RMMNetLock RMM Docs
III — How-To Guides

Recover access to the Web Console

Reset a forgotten Web Console password on a self-hosted deployment directly in the database.

Recover access to the Web Console

Self-hosted only: This guide applies to self-hosted deployments. On cloud, you have no host or database access — contact NetLock RMM support to regain access to your Console.

Use this guide when you forgot your Console password and no other account can reset it for you. You set the account's password to a known temporary value directly in the database and mark it for a forced password change. At the next sign-in, the Console asks you for a new password.

Before you start

Tip: If another account with users_edit can still sign in, it can reset your password in the Console instead: Users → User Settings → Reset Password (see Reset Password). You do not need this guide then.

You need:

  • Shell access with sudo on the host that runs the NetLock RMM containers.

  • The username of the account. The Console signs you in by username, not by email address.

  • The database credentials. The Console's appsettings.json is stored encrypted, so read them from the Docker setup instead. Option A reads them from the container automatically. For Option B, print them with:

    sudo grep -E 'MYSQL_(ROOT_PASSWORD|DATABASE)' /home/netlock/docker-compose.yml

    MYSQL_ROOT_PASSWORD is the password of the database user root, and MYSQL_DATABASE is the NetLock RMM database.

Note: The root password from the compose file only applies when the database is first created. If someone changed the root password later, use the current one. Installs from the guided installer also have a dedicated database user; its name and password are in /home/netlock/mysql/init/01_create_app_user.sql.

The temporary password hash used below is the BCrypt hash of the password admin:

$2a$11$KIDo.90Gv0jaEOi8ZH.JYuQzrD3YXlptkL0hIKABtxB5UqcNZbNWy

Option A — Command line

This is the shortest path. It opens no port and restarts nothing.

  1. Open a MySQL prompt inside the database container:

    sudo docker exec -it mysql-container sh -c 'mysql -u root -p"$MYSQL_ROOT_PASSWORD" "$MYSQL_DATABASE"'

    If your container has a different name, list the names with sudo docker ps --format '{{.Names}}'.

  2. List the accounts and note the username and state of yours:

    SELECT id, username, mail, auth_mode, enabled, two_factor_enabled FROM accounts;
  3. Set the temporary password and the forced reset. Replace your-username with the username from step 2:

    UPDATE accounts
       SET password = '$2a$11$KIDo.90Gv0jaEOi8ZH.JYuQzrD3YXlptkL0hIKABtxB5UqcNZbNWy',
           reset_password = 1
     WHERE username = 'your-username';
    EXIT;

Note: Type the statement at the MySQL prompt. Do not pass it on the command line with mysql -e "...": inside double quotes the shell replaces $2a and $11, and the stored hash no longer matches admin.

Continue with Sign in and set a new password.

Option B — Graphical tool (HeidiSQL)

Use this option if you prefer a graphical database tool such as HeidiSQL. The steps use HeidiSQL; DBeaver or MySQL Workbench work the same way. The database port is published on the host's loopback address only, and you reach it through SSH.

  1. Open the compose file:

    sudo nano /home/netlock/docker-compose.yml

    Under the mysql: service, add the following block, indented like volumes::

        ports:
          - '127.0.0.1:3306:3306'

    Warning: Bind the port to 127.0.0.1 only. A plain '3306:3306' publishes the database on every network interface, and Docker's published ports bypass host firewalls such as ufw. Your database would then be reachable from the internet.

    Note: Installs set up with the installer's external MySQL access option already publish port 3306 under mysql:. In that case, skip this step, step 2 and step 5.

  2. Restart the stack:

    sudo docker compose -f /home/netlock/docker-compose.yml down && sudo docker compose -f /home/netlock/docker-compose.yml up -d

    On hosts with the standalone binary, use docker-compose instead of docker compose.

  3. Connect through SSH. In HeidiSQL, create a session with the network type MariaDB or MySQL (SSH tunnel):

    • On the SSH tunnel tab: the server address, your SSH user and your SSH key or password.
    • On the Settings tab: host 127.0.0.1, port 3306, user root and the MYSQL_ROOT_PASSWORD value.

    For any other tool, open the tunnel yourself with ssh -L 3307:127.0.0.1:3306 your-ssh-user@your-server and connect the tool to 127.0.0.1, port 3307.

  4. Open the NetLock RMM database (the MYSQL_DATABASE value), then the accounts table, and find the row with your username:

    • Set password to the hash from Before you start.
    • Set reset_password to 1.
    • Save the row.
  5. After you have set a new password (next section), remove the two ports: lines from the compose file again and run the restart command from step 2.

Sign in and set a new password

Warning: Until you finish this step, the account accepts the publicly known password admin. Sign in right after the database change, and do not choose admin or another weak password as the new one — the Console does not stop you.

  1. Open the Console and sign in with your username and the password admin.
  2. The Console shows Choose your new password. Enter a strong new password twice and confirm.

You are then signed in. All other sessions of the account end, and the Audit log records Password reset (forced).

If the sign-in still fails

The password reset does not change any other sign-in requirement. Check the SELECT output from Option A, or the account row in Option B, and run the matching statement the same way as the UPDATE above. Replace your-username with your username.

StateEffectFix
auth_mode is SSOPassword sign-in is refused with Incorrect user name or password.UPDATE accounts SET auth_mode = 'Password & SSO' WHERE username = 'your-username';
enabled is 0The account is suspended; sign-in is refused with the same message.UPDATE accounts SET enabled = 1 WHERE username = 'your-username';
2FA is on and the authenticator is lostThe Console asks for the 2FA code before the password change.UPDATE accounts SET two_factor_account_secret_key = '', two_factor_secret_encrypted = 0, two_factor_last_step = 0 WHERE username = 'your-username'; — 2FA stays on, and you enrol a new authenticator at the next sign-in.
The account has a passkey that is lostThe Console asks for the passkey after the password.DELETE FROM account_passkeys WHERE account_id = 42; — replace 42 with the id of your account.
Too many failed attemptsSign-in is blocked temporarily.Wait 60 minutes, or restart the Web Console with sudo docker restart netlock-rmm-web-console. The Option B restart clears it as well.

Note: On older versions, some of these columns do not exist yet, and MySQL reports Unknown column. Skip that fix.

Clean up

  • Option B: the ports: lines are removed again and the stack is restarted.
  • If you cleared 2FA, the account has enrolled a new authenticator.
  • The Audit log shows the Password reset (forced) entry for your account.