Managed Host Stuck in UEFI Setup v2.2 New

View as Markdown

Use this playbook when a managed host remains at HostInitializing/UefiSetup/SetUefiPassword and the controller reports a Redfish Bios.ChangePassword failure.

Symptoms

  • Machine history reaches setuefipassword and does not advance.
  • NICo logs report HTTP 400 from Bios.ChangePassword.
  • The BMC reports that OldPassword is absent or has an unsupported format.

Inspect the recent state history:

nico-admin-cli -f json machine show <machine-id> \
| jq -r '.events[] | "\(.time) \(.event)"' \
| tail -10

Cause

The password known to NICo does not match the UEFI password on the BMC. This can happen after force-deletion when NICo cannot resolve the required credential or cannot reach the BMC during its best-effort UEFI cleanup. On re-ingestion, the BMC rejects the password-change request and host initialization cannot continue.

NICo force-deletion attempts to clear a recorded host UEFI password before removing the machine. It logs a warning and continues when that cleanup cannot complete. The --delete-bmc-credentials option removes saved BMC login credentials; it does not request UEFI-password cleanup.

Clear the Recorded UEFI Password

Request UEFI-password clearing for the affected host:

nico-admin-cli host clear-uefi-password --query <machine-id>

The command also accepts a host MAC address. NICo must have a recorded UEFI password and enough BMC information to select the current credential. When no password is recorded, the command returns a successful no-op and the controller logs No UEFI password is recorded as set on this host; nothing to clear. Do not repeatedly run the command in that case; use the BMC procedure below to reconcile the device state.

Reconcile the BMC Directly

When NICo cannot clear the password from its recorded state, use the Redfish command with the password configured on the BMC. Obtain BMC and UEFI credentials from your approved credential store. Read the current UEFI password into a shell variable without recording it in shell history:

read -r -s -p 'Current UEFI password: ' CURRENT_UEFI_PASSWORD
printf '\n'
nico-admin-cli redfish \
--address <bmc-ip-address> \
--username <bmc-username> \
--password <bmc-password> \
change-uefi-password \
--current-password "${CURRENT_UEFI_PASSWORD}" \
--new-password ''
unset CURRENT_UEFI_PASSWORD

After the BMC accepts the clear operation, allow the NICo state controller to retry SetUefiPassword and apply the configured site credential.

Do not force-delete the machine again as the first remediation. Preserve its state and logs until you have confirmed why UEFI cleanup or credential selection failed.

Verify Recovery

  1. Confirm that state history advances past setuefipassword:

    nico-admin-cli -f json machine show <machine-id> \
    | jq -r '.events[] | "\(.time) \(.event)"' \
    | tail -10
  2. Confirm that the host leaves HostInitializing/UefiSetup.

  3. Confirm that NICo logs no longer report a Bios.ChangePassword failure for the host.

For force-deletion behavior and its cleanup options, refer to Force Deleting and Rebuilding Hosts.