"Access Denied" error when using SSH to log in to the vCenter appliance
search cancel

"Access Denied" error when using SSH to log in to the vCenter appliance

book

Article ID: 327081

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

Logging in to vCenter Server through SSH fails with Access Denied error, set the default shell for the user to bash.

  • SSH login to the vCenter Server Appliance fails.
  • The error message displayed is: "Access Denied"

You may also experience the following:

  • Returned to the login screen again.
  • Logging in to the VAMI (https://VC_IP:5480) using same credentials is successful.
  • Using the virtual machine console to log in fails with the error:

    Invalid Shell

    Note: This error is only displayed briefly
     
  • In the /var/log/messages.log file, similar entries similar are seen:

    YYYY-MM-DDTHH:MM:SS vc sshd[23037]: User root not allowed because shell /bin/bosh does not exist

Environment

  • vCenter Server 6.x
  • vCenter Server 7.x
  • vCenter Server 8.x

Cause

This issue occurs when the default shell for a user is set to an invalid shell.

Follow these steps to verify if the issue is caused by an invalid shell configuration:

  1. To enter the GRUB menu, reboot the VCSA
  2. Press 'e' as soon as the Photon OS splash screen appears to enter edit mode.
  3. Locate the line that begins with the word Linux.
  4. Append rw init=/bin/bash to the end of the line.
  5. Press F10 to continue the boot process.
  6. Once the appliance has booted, run the following command to remount the root file system with read-write permissions: mount -o remount,rw /
  7. Run this command to see the shell settings for the users: cat /etc/passwd

    For example:
    ...
    root:x:0:0:root:/root:/bin/appliancesh
    ...
  8. The root entry should be root:x:0:0:root:/root:/bin/appliancesh.

If this entry does not contain /root:/bin/appliancesh review the /root/.bash_history file to see if an invalid shell was set with this command:

less /root/.bash_history

For example:

#1468577177
chsh -s "/bin/bosh" root

Note: In the example above the root user has incorrectly set the shell to "/bin/bosh". The line above is the timestamp of this event in epoch format.

Resolution

Prerequisite: Make sure to have a full backup or a snapshot of the vCenter Appliance before proceeding.
If the vCenter is in Enhanced Linked Mode (ELM), ensure that offline snapshots are taken simultaneously for all vCenter servers part of the same SSO domain. VMware vCenter in Enhanced Linked Mode pre-changes snapshot (online or offline) best practice

To resolve this issue, set the default shell for the user to bash:

  1. To enter the GRUB menu, reboot the VCSA and press 'e' as soon as the Photon OS splash screen appears
  2. Locate the line that begins with the word Linux.
  3. Append rw init=/bin/bash to the end of that line
  4. Press F10 to continue the boot process
  5. Set the default Shell to BASH by running this command: chsh -s /bin/bash root
  6. Run this command to see the shell settings for the users: cat /etc/passwd  
  7. Post verifying, VCSA can be rebooted. 
     

Additional Information