"Identity Source LDAP Certificate is about to expire""Invalid credentials" errors on vCenter login screen with domain credentials if the certificate is expired, renewed or updated/changed/var/log/vmware/sso/ssoAdminServer.log will report the following warnings and error traces.YYYY-MM-DD HH:MM:SS WARN ssoAdminServer [548 : pool-2-thread-8] [OpId=####-####-####-###-##:] [com.vmware[ldaps: //<<server_name>>: 636, CN=#####, CN=User cannot bind connection:
YYYY-MM-DD HH:MM:SS ERROR ssoAdminServer [548 : pool-2-thread-8] [OpId=####-####-####-###-##:] [com.vmware. identity.idm.server. ServerUtils] cannot establish ldap connection with URI: [ldaps://<<server_name>> : 636]because [com. vmware.identity. interop. ldap. ServerDownLdapException] with reason [Can't contact LDAP server] therefore will try to attempt to use secondary URIs, if applicableYYYY-MM-DD HH:MM:SS ERROR ssoAdminServer [548 : pool-2-thread-8] [OpId=####-####-####-###-##:] [com.vmware.identity.idm.server. Provider. BaseLdapProvider] com. vmware. identity. interop. ldap. ServerDownLdapException: Can't contact[code: -1]YYYY-MM-DD HH:MM:SS ERROR ssoAdminServer [548 : pool-2-thread-8] [OpId=####-####-####-###-##:] [com.vmware.identity.idm.server. IdentityManager] Failed to find person users [Criteria : searchString=, domain=######] in tenant [vsphere. local]YYYY-MM-DD HH:MM:SS ERROR ssoAdminServer [548 : pool-2-thread-8] [OpId=####-####-####-###-##:] [com.vmware.identity.idm.server. ServerUtils] Exception 'com. vmware. identity. interop. ldap. ServerDownLdapException: Can't contact LDAP server\nLDAPcom. vmware. identity. interop. ldap. ServerDownLdapException: Can't contact LDAP server
VMware vCenter Server 8.x
/opt/vmware/bin/sso-config.sh -get_identity_sourcesopenssl s_client -connect domain_controller.example.com:636 -showcertsUse proper certificate files for VC LDAPS IdP configuration:
Fails to save LDAPS configuration if trying to edit the existing configuration:
You can use the vCert tool to update the LDAPS certificates without removing and recreating the identity provider in vSphere with option 3 followed by option 11. If the vCenter is in ELM this will also remediate the other nodes of the ELM with no additional steps or service restarts.