What you do is not really common for many people on the forum; so that may be why you don't get a response.
Many use an external AAA server, RADIUS or TACACS, so you won't have the issue that you forget the password. That also has the benefit that you have a centralized audit of who logged in when (and with TACACS accounting also did what). Then there is a manager password stored somewhere securely in case the external authentication is broken, and the reset button as the very last resort (but should never happen).
But the authorization you suggested could work as well, but I've never tried it.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Jul 08, 2025 08:26 AM
From: damianhlozano
Subject: Reset password on 2930F stack
Hello team!!
I have 3 switches Aruba 2930F in an stack.
So far, all 3 switches are working fine, and we have access. The stack is in production and we should not lost access.
We have only the manager and operator passwords, but now we need to create another user with full access to everything.
Just in case, if something wrong happens, I will need to reset the password for the stack.
In the "Management and configuration guide", I see that I can reset the password by pressing the clear button, for 1-5 seconds, but I dont know what happen when the switch is in an stack.
The manager and operator passwords of the stack will be reset if I press the clear button in any switch in the stack?
I need to press clear button in all 3 switches or just the primary?
The clear button is in case that something wrong happen,(Plan B). This is what I plan to execute first to add another admin user (Plan A)
I connect to the stack IP using telnet and then execute this:
-configure
-aaa authorization group "Admins" 100 match-command "configure" permit
-aaa authorization group "Admins" 200 match-command "enable" permit
-aaa authorization group "Admins" 300 match-command "any" permit
-aaa authentication local-user AdminIT group Admins password plaintext -> The password should be asked
-exit
-write memory
Do you think this will work?
Thanks in advance.
Regards,
Damián