diff --git a/servers/pfi-tacticalrmm/README.md b/servers/pfi-tacticalrmm/README.md index 1444b21..6f75d6d 100644 --- a/servers/pfi-tacticalrmm/README.md +++ b/servers/pfi-tacticalrmm/README.md @@ -47,6 +47,11 @@ Monitors and manages endpoints, pushes patches, runs scripts, etc. `update.sh` only touches the compression keys of `config.json`, so a WANonly change survives updates. - Device groups: `TC2-MacMini` (agent group), `PFI-AMT` (mtype 1, Intel AMT only; created by Prime 2026-10-02, empty). 24 devices visible to Prime's account, 7 of them report Intel AMT. +- **Site-admin account `lkraven` (2026-10-02, Prime):** full site admin (users, server files), full rights on + `PFI-AMT` and `TC2-MacMini`; password vaulted `pfi-tacticalrmm/meshcentral-lkraven-password`. Created with + `node node_modules/meshcentral --createaccount lkraven --hashpass ` + `--adminaccount lkraven` while + the service was stopped (the CLI writes the DB directly). TacticalRMM's mesh sync only manages `name___N` + accounts, so it leaves this one alone. TRMM's own MeshCentral superuser is `fosxggiw`. ⚠ Not in 2FA yet. - CLI access: `meshctrl.js` on this host with Prime's login token, vaulted `pfi-tacticalrmm/meshcentral-login-token` (one line: `username: ~t:… password: …`). Example: `sudo -n -u tactical node /meshcentral/node_modules/meshcentral/meshctrl.js listdevicegroups --url wss://rmm-mesh.phasefinal.com --loginuser --loginpass

`.