Service accounts used for third-party integrations, such as backup tools (e.g., Veeam) or Telco Cloud Automation (TCA), often require passwords that do not expire. In the vCenter Server user interface, password expiry is a global parameter that affects all users.
This article provides instructions on using the dir-cli utility to configure a "never expires" attribute for specific Single Sign-On (SSO) accounts without modifying the global policy.
When a service account password expires, third-party integrations fail. The /var/log/vmware/sso/websso.log file contains errors similar to the following:
yyyy-mm-ddThh:mm:ss.mssZ ERROR websso[56:tomcat-http--18] [CorId=29b33506-52fe-42c1-96ad-451a7e609e5a] [com.vmware.identity.idm.server.IdentityManager] Failed to authenticate principal [<user_name>@<SSO_Domain>]. User password expired.yyyy-mm-ddThh:mm:ss.mssZ INFO websso[56:tomcat-http--18] [CorId=29b33506-52fe-42c1-96ad-451a7e609e5a] [com.vmware.identity.idm.server.IdentityManager] Authentication failed for user [<user_name>@<SSO_Domain>] in tenant [<SSO_Domain>] in [23] milliseconds with provider [<SSO_Domain>] of type [com.vmware.identity.idm.server.provider.vmwdirectory.VMwareDirectoryProvider]yyyy-mm-ddThh:mm:ss.mssZ ERROR websso[56:tomcat-http--18] [CorId=29b33506-52fe-42c1-96ad-451a7e609e5a] [com.vmware.identity.idm.server.ServerUtils] Exception 'com.vmware.identity.idm.PasswordExpiredException: User account expired: {Name: <user_name>, Domain: <SSO_Domain>}'com.vmware.identity.idm.PasswordExpiredException: User account expired: {Name: <user_name>, Domain: <SSO_Domain>}com.vmware.identity.idm.PasswordExpiredException: User account expired: {Name: <user_name>, Domain: <SSO_Domain>}
VMware vCenter Server
The vCenter Server UI only supports global password policy configuration. Individual account overrides for password expiration must be performed via the command-line interface using the dir-cli tool.
Follow these steps to modify the password expiry attribute for a specific SSO user.
shell to access the BASH shell./usr/lib/vmware-vmafd/bin/dir-cli user find-by-name --account <Account Name> --level 2/usr/lib/vmware-vmafd/bin/dir-cli user modify --account <Account Name> --password-never-expiresadministrator@vsphere.local (or the equivalent SSO administrator).root password will result in an ERROR_LOGON_FAILURE (1326).Password never expires: TRUE/usr/lib/vmware-vmafd/bin/dir-cli user modify --account <Account Name> --password-expires
For more functions of this utility, refer to the dir-cli Command Reference documentation.
Example snippets:
Set the password expiry to "never":
# /usr/lib/vmware-vmafd/bin/dir-cli user modify --account test --password-never-expiresEnter password for administrator@vsphere.local:Password set to never expire for [<User_Name>].
Validation:
# /usr/lib/vmware-vmafd/bin/dir-cli user find-by-name --account <User_Name> --level 2Enter password for administrator@vsphere.local:Account: <User_Name>UPN: <User_Name>@<SSO_DOMAIN>Account disabled: FALSEAccount locked: FALSEPassword never expires: TRUEPassword expired: FALSEPassword expiry: N/A