# Cannot change medic password

**URL:** <https://forum.communityhealthtoolkit.org/t/cannot-change-medic-password/1877>\
**Category:** Technical Support\
**Created:** [May 11, 2022, 11:58am UTC](https://forum.communityhealthtoolkit.org/t/cannot-change-medic-password/1877 "2022-05-11T11:58:27Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![raf](https://communityhealthtoolkit.b-cdn.net/letter_avatar_proxy/v4/letter/r/848f3c/32.png) [@raf](https://forum.communityhealthtoolkit.org/u/raf)\
**Post date:** [May 11, 2022, 11:58am UTC](https://forum.communityhealthtoolkit.org/t/cannot-change-medic-password/1877/1 "2022-05-11T11:58:27Z")

</div>

Dear all,

On one of your instance we have successfully changed the password for the admin user `medic`.  
On a second instance, we run into this [issue](https://forum.communityhealthtoolkit.org/t/updating-default-login-credentials/1178):

```auto
https://forum.communityhealthtoolkit.org/t/updating-default-login-credentials/1178

```

I was wondering why this problem seems not to be reproducible and what to do to make the password change, using the graphical interface. We do not want users have to write too many commands, in the DB.

Best regards.

---

<div class="post-metadata">

**Author:** ![diana](https://communityhealthtoolkit.b-cdn.net/user_avatar/forum.communityhealthtoolkit.org/diana/32/2049_2.png) [@diana](https://forum.communityhealthtoolkit.org/u/diana)\
**Post date:** [May 11, 2022, 12:52pm UTC](https://forum.communityhealthtoolkit.org/t/cannot-change-medic-password/1877/2 "2022-05-11T12:52:14Z")

</div>

Hi @raf

Which version of the app are you trying this on?  
As of `3.14.0`, this should be fixed via [Changing admin password via webapp doesn't work · Issue #6986 · medic/cht-core · GitHub](https://github.com/medic/cht-core/issues/6986) .

---

<div class="post-metadata">

**Author:** ![raf](https://communityhealthtoolkit.b-cdn.net/letter_avatar_proxy/v4/letter/r/848f3c/32.png) [@raf](https://forum.communityhealthtoolkit.org/u/raf)\
**Post date:** [May 11, 2022, 1:47pm UTC](https://forum.communityhealthtoolkit.org/t/cannot-change-medic-password/1877/3 "2022-05-11T13:47:48Z")

</div>

We are using 3.9.0  
We will discuss internally to update.

---

<div class="post-metadata">

**Author:** ![sanjay](https://communityhealthtoolkit.b-cdn.net/user_avatar/forum.communityhealthtoolkit.org/sanjay/32/1409_2.png) [@sanjay](https://forum.communityhealthtoolkit.org/u/sanjay)\
**Post date:** [March 8, 2023, 6:01am UTC](https://forum.communityhealthtoolkit.org/t/cannot-change-medic-password/1877/4 "2023-03-08T06:01:22Z")

</div>

Any Update for the version 4 here regarding the password change ? We recently changed for one of the instances and seems to be not working.

[Admin pass change in CHT 4.x breaks CHT, shows wrong error message · Issue #8096 · medic/cht-core · GitHub](https://github.com/medic/cht-core/issues/8096) we followed the given link as the part of references document.

For the context we are using CHT 4.1, in regards to the issue we are also following this reference

> <https://github.com/medic/cht-core/issues/8096>
>
> \*\*Describe the bug\*\*
> A clear and concise description of what the bug is.
> 
> \*\*T…o Reproduce\*\*
> Steps to reproduce the behavior:
> 1. Spin up a CHT 4.1.0 instance using \[CHT Docker Helper\](https://docs.communityhealthtoolkit.org/apps/guides/hosting/4.x/app-developer/#cht-docker-helper-for-4x)
> 2. login as user \`medic\` , password \`password\`
> 3. go to hamburger menu -\> user settings -\> update password
> 4. change password
> 5. Password change is accepted, but an error is shown stating it wasn't accepted "Password is not correct."
> 6. CHT instance stops working because the \`COUCHDB\_PASSWORD\` value in the environment variable file is now wrong
> 
> \*\*Expected behavior\*\*
> Either password change is not allowed because it will break CHT or password change works and all services use new password
> 
> \*\*Logs\*\*
> \`\`\`
> \<150\>Feb 22 00:02:23 haproxy\[25\]: 172.19.0.7,couchdb,201,12,0,0,PUT,/\_users/org.couchdb.user%3Amedic,api,medic,'{"\_id":"org.couchdb.user:medic","\_rev":"1-5b7bf3319f91c46105aa45fbef077b6c","name":"medic","type":"
> user","roles":\["admin"\],"password":"\*\*\*"}',414,10,85,'node-fetch/1.0 (+https://github.com/bitinn/node-fetch)' \<150\>Feb 22 00:02:23 haproxy\[25\]: 172.19.0.7,couchdb,200,3,0,0,GET,/\_node/\_local/\_config/admins,-,medic,'-',324,2,97,'-' \<150\>Feb 22 00:02:23 haproxy\[25\]: 172.19.0.7,couchdb,200,3,0,0,GET,/\_membership,-,medic,'-',253,1,74,'-'                                                                                                 
> \<150\>Feb 22 00:02:23 haproxy\[25\]: 172.19.0.7,couchdb,200,7,0,0,PUT,/\_node/couchdb@127.0.0.1/\_config/admins/medic?raw=true,-,medic,'"-pbkdf2-21c4d152c87449a1cf60fd0989ca25f1307b1dc2,5b5034cec58639daf2022ab6e890c1358b604b9d,10"',314,5,87,'-'
> \<150\>Feb 22 00:02:23 haproxy\[25\]: 172.19.0.7,couchdb,401,1,0,0,PUT,/medic/org.couchdb.user%3Amedic,api,medic,'{"\_id":"org.couchdb.user:medic","\_rev":"2-7035a74129b2bf8ff30347b2e51c4e59","name":"medic","type":"user-settings","roles":\["admin"\],"known":true}',359,0,67,'node-fetch/1.0 (+https://github.com/bitinn/node-fetch)'
> \<145\>Feb 22 00:02:27 haproxy\[25\]: Server couchdb-servers/couchdb is DOWN, reason: Layer7 wrong status, code: 0, info: "via agent : down", check duration: 208ms. 0 active and 0 backup servers left. 6 sessions active, 0 requeued, 0 remaining in queue.
> \<144\>Feb 22 00:02:27 haproxy\[25\]: backend couchdb-servers has no server available! \[WARNING\] 052/000227 (25) : Server couchdb-servers/couchdb is DOWN, reason: Layer7 wrong status, code: 0, info: "via agent : down", check duration: 208ms. 0 active and 0 backup servers left. 6 sessions active, 0 requeued, 0 remaining in queue. \[ALERT\] 052/000227 (25) : backend 'couchdb-servers' has no server available! 
> \`\`\`
> 
> \*\*Screenshots\*\*
> !\[image\](https://user-images.githubusercontent.com/8253488/220491302-6ae96812-42be-4c91-9b07-03e1b2baa558.png)
> 
> 
> \*\*Video\*\*
> 
> https://user-images.githubusercontent.com/8253488/220491551-2609e50b-3827-4fc8-beed-59c6e6b1071b.mp4
> 
> 
> \*\*Environment\*\*
> \- Instance: local dev
> \- Browser: latest FF
> \- Client platform: ubuntu 
> \- App: webapp
> \- Version: 4.1.0
> 
> \*\*Additional context\*\*
> 
> The fix is to edit the \`COUCHDB\_PASSWORD\` value in the environment variable file (\`cht-core/scripts/docker-helper-4.x/\*\` in the case of Docker Helper) so that the env file password matches the new one you just changed it to. Restart containers and everything works again.
> 
> Related tickets:
> \* #8076 - discovered here
> \* #6986 - possibly the last time this behavior was changed?

!!Urjent!! seeking solutions.

cc @nitin @niraj @gkesh@gaarimasharma @binod

---

<div class="post-metadata">

**Author:** ![henok](https://communityhealthtoolkit.b-cdn.net/user_avatar/forum.communityhealthtoolkit.org/henok/32/576_2.png) [@henok](https://forum.communityhealthtoolkit.org/u/henok)\
**Post date:** [March 8, 2023, 7:19am UTC](https://forum.communityhealthtoolkit.org/t/cannot-change-medic-password/1877/5 "2023-03-08T07:19:39Z")

</div>

@sanjay assuming you used [this](https://docs.communityhealthtoolkit.org/apps/guides/hosting/4.x/self-hosting-single-node/) guideline to set up CHT 4, go to the `.env` file and edit the `COUCHDB_PASSWORD` and put in your new password and restart the containers. Let me know if that solves the issue.

---

<div class="post-metadata">

**Author:** ![gkesh](https://communityhealthtoolkit.b-cdn.net/user_avatar/forum.communityhealthtoolkit.org/gkesh/32/1313_2.png) [@gkesh](https://forum.communityhealthtoolkit.org/u/gkesh)\
**Post date:** [March 8, 2023, 10:13am UTC](https://forum.communityhealthtoolkit.org/t/cannot-change-medic-password/1877/6 "2023-03-08T10:13:09Z")

</div>

The issue has been solved but it was a little multifaceted than initially thought. The problem is something that has been identified and posted about in the GitHub repository in the post quoted by @sanjay sir above. This is an issue that existed in CHT version 3.x and was extensively discussed in the github issue [here](https://github.com/medic/cht-core/issues/6986#issue-824041301).

To explain briefly, the problem occurs when you attempt to update the password for the user `medic`. Once you press submit on the `Change Password` dialog, it displays an error as shown below.

 ![220491302-6ae96812-42be-4c91-9b07-03e1b2baa558](https://communityhealthtoolkit.b-cdn.net/uploads/default/original/2X/a/a38672e3f7ba488465d6c767d9a17bc9d8aeddbc.png)

> Note: The image was pulled from [here](https://github.com/medic/cht-core/issues/8096), since we didn’t get a chance to snap a screenshot when we were working on it. If you keep pressing submit after this, it says error saving changes.

After this, the system stops working entirely. You cannot login regardless of which password you use, the new password or the old password. Our solution involved restoring the original password to medic to get the system working at least.

First idea was to change the password using the `local.ini` file inside `/opt/couchdb/etc` as stated in the community post [here](https://forum.communityhealthtoolkit.org/t/updating-default-login-credentials/1178). But even after adding `medic = OldPassword` under the `[admins]` section and restarting the `cht_couchdb_1` container, it was not getting hashed or updated like it was supposed to. If anyone has an idea on why this approach was not working on CHT 4, please reply to my comment on the post.

Second idea was to update the user document using the instructions on the [CouchDB documentation](https://docs.couchdb.org/en/stable/intro/security.html). This approach required us to fetch the user document from medic using curl and use the `rev` to update the document. The following query was used to update the document but ultimately failed.

```bash
curl -X PUT http://medic:NewPassword@localhost:5984/_users/org.couchdb.user:medic \
     -H "Accept: application/json" \
     -H "Content-Type: application/json" \
     -d '{"name": "medic", "password": "OldPassword", "roles": ["admin"], "type": "user"}'

```

After running this command, it does show the expected result as shown below:

```json
{"ok":true,"id":"org.couchdb.user:medic","rev":"x-xxxxxxxxxxxxxxxxxxxxxxxxx"}

```

But even with this response, the password was not updated. The same issue persisted.

Third idea and the one that really worked was to follow the suggestion mentioned by `latin-panda` on **issue#6986**. We used the node `couchdb@127.0.0.1` and the following command:

```bash
curl -s -X PUT http://medic:NewPassword@localhost:5984/_node/couchdb@127.0.0.1/_config/admins/medic -d '"OldPassword"'

```

This worked exactly as intended in our local test instance but failed to work on the actual server.

> Note: The command above will revert the password to original, if your intention is to get your server up and running quickly, this is the best option. Remember to replace **NewPassword** and **OldPassword** with whatever you used in your case.

If the command worked correctly, it will output the hashed and salted version of the password like this:

```bash
$ curl -s -X PUT http://medic:NewPassword@localhost:5984/_node/couchdb@127.0.0.1/_config/admins/medic -d '"OldPassword"'
"-pbkdf2-2d86831c82b440b8887169bd2eebb356821d621b,5e11b9a9228414ab92541beeeacbf125,10"

```

In our actual instance this did not happen and the password was not changed. The reason behind it was special characters. In our new password, we had special a character, ‘@’. This caused the URL to be misinterpreted by the `curl` command. To remedy this, we used URL encoded version of ‘@’ which is ‘%40’. So the command in the end for password ‘P@ssword’ would be as follows:

```bash
$ curl -s -X PUT http://medic:P%40ssword@localhost:5984/_node/couchdb@127.0.0.1/_config/admins/medic -d '"OldPassword"'

```

Finally this was the solution that worked and helped us get our instance up and running.

> Note: For CHT 3.17.1 deployments, we have been using special characters in the password. It works in the ‘cht’ command without any problems if we simply put the password inside double quotes but that approach did not work in this case.

```bash
# Does not work
curl -s -X PUT http://medic:"P@ssword"@localhost:5984/_node/couchdb@127.0.0.1/_config/admins/medic -d '"OldPassword"'

# Works in CHT 3.17.1
cht --url=https://medic:"P@ssaword"@localhost --accept-self-signed-certs

```

There are still a few unanswered questions which our team will do some research on. We hope that this bug will get patched as soon as possible or at least the option to change the medic password from the Web UI will get removed.
