YYYY-MM-DDTHH:MM:SS.xxxZ WARN <vc-fqdn>:federation (federation-business-pool-0) [CUSTOMER;-;xxx.xx.xx.xxx;xxxxxxxx-cxxx-xxxx-xxxx-xxxxxxxxxxxx;] com.vmware.vidm.federation.authenticator.oidc.OidcAuthenticator - Exception occurred while retrieving oidc tokens com.vmware.vidm.federation.authenticator.oidc.OidcTokenValidationException: Issue time in ID token is invalid
at com.vmware.vidm.federation.authenticator.oidc.OidcAuthenticationValidator.validateIssueTime(OidcAuthenticationValidator.java:206)
at com.vmware.vidm.federation.authenticator.oidc.OidcAuthenticationValidator.validateIDToken(OidcAuthenticationValidator.java:162)
at com.vmware.vidm.federation.authenticator.oidc.OidcAuthenticator.lambda$processResponse$3(OidcAuthenticator.java:150)
at java.base/java.util.concurrent.CompletableFuture$UniCompose.tryFire(Unknown Source)
at java.base/java.util.concurrent.CompletableFuture$Completion.run(Unknown Source)
at com.vmware.vidm.common.async.ContextPassingExecutor.lambda$wrap$0(ContextPassingExecutor.java:48)
at io.micrometer.core.instrument.internal.TimedRunnable.run(TimedRunnable.java:49)
at java.base/java.util.concurrent.ForkJoinTask$RunnableExecuteAction.exec(Unknown Source)
at java.base/java.util.concurrent.ForkJoinTask.doExec(Unknown Source)
at java.base/java.util.concurrent.ForkJoinPool$WorkQueue.topLevelExec(Unknown Source)
at java.base/java.util.concurrent.ForkJoinPool.scan(Unknown Source)
at java.base/java.util.concurrent.ForkJoinPool.runWorker(Unknown Source)
at java.base/java.util.concurrent.ForkJoinWorkerThread.run(Unknown Source)
VMware vCenter Server 8.0.1 and later
For Okta to validate tokens (e.g., OAuth, OIDC, or SAML tokens), the system time on the interacting devices must be synchronized with Okta's server time within a 5-minute window. If there is a time mismatch between the local system and vCenter, it may result in token validation errors, leading to login attempts being denied with an "access denied" message.
To verify timestamps.
watch -d date -u
Documentations to follow for testing and fixing time sync issues:Configuring Time Synchronization Settings in vCenter Server