Root and Service accounts are disconnected in SDDC Manager after changing the password expiry to shorter period.
search cancel

Root and Service accounts are disconnected in SDDC Manager after changing the password expiry to shorter period.

book

Article ID: 370453

calendar_today

Updated On:

Products

VMware SDDC Manager / VCF Installer

Issue/Introduction

  • Service account and root account passwords for ESXi show disconnected in the SDDC manager after changing the password expiration time in ESXi.
  • Wrong password noted for root and ESXi service account, which doesn't match the password saved in the SDDC database. 
  • ESXi passwords were changed outside the SDDC workflow
  • Unable to remediate ESXi svc-esxifqdn@domain service account password.

Environment

SDDC Manager 4.x

SDDC Manager 5.x

Cause

Changing the password expiration for the svc and root accounts in ESXi to a shorter date then when the password was last changed will cause the passwords to immediately expire and SDDC manager to show the passwords are disconnected.

Resolution

To resolve this issue, change the SVC account password in ESXi to a new password to clear the expiration and then remediate the password in SDDC manager.

To change the svc account password in ESXi, please follow below steps:

  1. Log in to the ESXi host UI directly using your root account.
  2. Navigate to Manage > Security & Users > Users.
  3. Select the svc-vcf-* service account, click Edit, and set a new password. This will clear the expiration status on the host.

    if svc-vcf account is missing, please refer to recreate missing account:Missing SDDC Manager Service account for an ESXi host 
  4. Log in to SDDC Manager and go to Password Management.
  5. Perform a Remediate Password for the service account first. Once it shows as "Connected," proceed to remediate the root account.

Additional Information

If you want to keep the same service account password, you can pull the service account passwords with the following KB: Retrieve the service accounts credentials from SDDC Manager