OPNsense Forum

English Forums => High availability => Topic started by: upscale4446 on June 29, 2026, 05:31:36 PM

Title: HA cluster syncing users & groups
Post by: upscale4446 on June 29, 2026, 05:31:36 PM
Hi all,
how are you dealing with users & groups for your HA cluster?
Are you syncing them and use the same root password or are you excluding users & groups from the sync in order to be able to use different passwords?
What's the best practice here?

Thanks & BR
Title: Re: HA cluster syncing users & groups
Post by: Patrick M. Hausen on June 29, 2026, 06:06:33 PM
We use personalised accounts for all admins (so we can track who logs in when) and sync them, because as an admin I fully expect to have a single set of credentials for all member machines of something naming itself a "cluster". The root user is not disabled but the password is 40 random characters long, never used, and stored in the safe so to speak, for emergency access.