Joining vCenter appliance to AD from cli fails with error "LW_ERROR_INVALID_MESSAGE error (code 0x00009c46)" and from UI it fails with error "Idm client exception: Error trying to join AD, error code [40006]"
book
Article ID: 341121
calendar_today
Updated On:
Products
VMware vCenter Server
Issue/Introduction
Logins to a vCenter Server Appliance or PSC using Active directory accounts fails with error "Authentication Failure".
The PSC or vCenter will still appear to be part of the AD on the SSO configuration.
While running the below command, you see the error LW_ERROR_INVALID_MESSAGE error (code 0x00009c46) /opt/likewise/bin/domainjoin-cli join domain.com Domain_Administrator Password
From UI we see error "Idm client exception: Error trying to join AD, error code [40006]"
In domainjoin.log we see similar entries
WARNING:Short domain name not specified. Defaulting to 'DOMAIN' ERROR:LW_ERROR_INVALID_MESSAGE [LW_ERROR_INVALID_MESSAGE]
For vCenter 6.5/8.0: /opt/likewise/bin/lwsm start lwio
Re-login to web client and add vCenter to AD
Additional Information
It may be necessary to have the appliance leave the AD before the fix, and rejoin it after the fix, if it is displayed as still being joined to the AD but the /opt/likewise/bin/lw-get-status returns Unknown as the name and status for the Domain Controller.