Error: "Insufficient permissions to perform this operation." during VRMS or SRM appliance registration
search cancel

Error: "Insufficient permissions to perform this operation." during VRMS or SRM appliance registration

book

Article ID: 389606

calendar_today

Updated On:

Products

VMware Live Recovery VMware vCenter Server 8.0

Issue/Introduction

  • LDAP user accounts with administrator privileges fail to register the appliance to vCenter.
  • Single Sign-On (SSO) user accounts with global administrator privileges also fail to register the appliance to vCenter.
  • Registering the appliance using administrator@mydomain/administrator@vsphere.local works as expected.

ERROR
Operation Failed
Insufficient permissions to perform this operation.
Operation ID: ########-####-####-####-############



  • The following logs can be found on the SRM:

/var/log/vmware/dr/drconfig.log: 

--> NOTE: Picked up JDK_JAVA_OPTIONS: --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.base/java.io=ALL-UNNAMED --add-opens=java.base/java.util=ALL-UNNAMED --add-opens=java.base/java.util.concurrent=ALL-UNNAMED --add-opens=java.rmi/sun.rmi.transport=ALL-UNNAMED
--> vSphere Replication Appliance configuration error:Unable to create solution user.
--> Details: Service account com.vmware.vr-sa-########-####-####-####-############ not found
--> [ msgId: com.vmware.vr.config.unable_to_create_user; value: null; errorStacktrace :  ]
-->     at com.vmware.hms.config.helper.ServiceAccountHelper.createServiceAccount(ServiceAccountHelper.java:143)
-->     at com.vmware.hms.config.VrConfig.createServiceAccount(VrConfig.java:552)
-->     at com.vmware.hms.config.VrConfig.reconfigVr(VrConfig.java:505)
-->     at com.vmware.hms.config.VrConfig.expressSetup(VrConfig.java:345)
-->     at com.vmware.hms.config.cli.command.ExpressSetup.run(ExpressSetup.java:59)
-->     at com.vmware.hms.config.cli.command.CommandBase.run(CommandBase.java:347)
-->     at com.vmware.hms.config.cli.App.run(App.java:146)
-->     at com.vmware.hms.config.cli.App.main(App.java:206)
--> Exception: NOTE: Picked up JDK_JAVA_OPTIONS: --add-opens=java.base/java.lang=ALL-UNNAMED --add-opens=java.base/java.io=ALL-UNNAMED --add-opens=ja
va.base/java.util=ALL-UNNAMED --add-opens=java.base/java.util.concurrent=ALL-UNNAMED --add-opens=java.rmi/sun.rmi.transport=ALL-UNNAMED
[YYYY-MM-DDTHH:MM:SS] info drconfig[03365] [SRM@6876 sub=ConfigureVrmsOp opID=1b45a309-####-####-####-############-configure:3fe5] Exiting Configu
reVrms
[YYYY-MM-DDTHH:MM:SS] verbose drconfig[03365] [SRM@6876 sub=vmomi.soapStub[128] opID=1b45a309-####-####-####-############-configure:3fe5] Resetting stub adapter; <[N7Vmacore4Http3Ext15DrUserAgentImplE:0x00007f932406b778], /lookupservice/sdk>, (null)
[YYYY-MM-DDTHH:MM:SS] error drconfig[03365] [SRM@6876 sub=ConfigureVrmsOp opID=1b45a309-####-####-####-############-configure:3fe5] Operation failed
--> (vmodl.fault.SystemError) {
-->    faultCause = (vmodl.MethodFault) null,
-->    faultMessage = <unset>,
-->    reason = "Failed to register VRMS."
-->    msg = ""
--> }
--> [context]zKq7AVECAAQAAGFXdAELZHJjb25maWcAACwZHGxpYnZtYWNvcmUuc28AATOWCmRyLWNvbmZpZ3VyYXRvcgABnwUFARoWEgGxKhEBDxYKAM4pNADSQjQA4H1JArCOAGxpYnB0aHJlYWQuc28uMAAD3/oPbGliYy5zby42AA==[/context]
[YYYY-MM-DDTHH:MM:SS] info drconfig[03365] [SRM@6876 sub=ConfigureVrmsOp opID=1b45a309-####-####-####-############-configure:3fe5] Exiting Start
[YYYY-MM-DDTHH:MM:SS] verbose drconfig[03803] [SRM@6876 sub=DrConfigConfigurationManager ctxID=7b2d2b09 opID=1b45a309-####-####-####-############-configure:3fe5] OnError: Configuration task failed

 

  • The following logs can be found on the vCenter Server:


/var/log/vmware/sso/ssoAdminServer.log:

[YYYY-MM-DDTHH:MM:SS] INFO ssoAdminServer[171:pool-2-thread-44] [OpId=2829aa4b-####-####-####-############] [com.vmware.identity.vlsi.SessionManagerImpl] User {Name: <AD-USER-ACCOUNT>, Domain: vmware.com} with role 'Administrator' logged in successfully.
[YYYY-MM-DDTHH:MM:SS] INFO ssoAdminServer[171:pool-2-thread-44] [OpId=91a7e0c3-####-####-####-############] [com.vmware.identity.vlsi.RoleBasedAuthorizer] User {Name: <AD-USER-ACCOUNT>, Domain: vmware.com} with role 'Administrator' is authorized for method call 'RoleManagementService.hasAdministratorRole'
[YYYY-MM-DDTHH:MM:SS] INFO ssoAdminServer[165:pool-2-thread-43] [OpId=91a7e0c3-####-####-####-############] [com.vmware.identity.admin.vlsi.RoleManagementServiceImpl] [User {Name: <AD-USER-ACCOUNT>, Domain: vmware.com} with role 'Administrator'] Checking Administrator role for user {Name: <AD-USER-ACCOUNT>, Domain: vmware.com}
[YYYY-MM-DDTHH:MM:SS] INFO ssoAdminServer[165:pool-2-thread-43] [OpId=91a7e0c3-####-####-####-############] [com.vmware.identity.admin.vlsi.RoleManagementServiceImpl] Vmodl method RoleManagementService.hasAdministratorRole return value is true


/var/log/vmware/vpxd/vpxd.log:

[YYYY-MM-DDTHH:MM:SS] info vpxd[1921986] [Originator@6876 sub=User opID=########] Login token: SamlToken [subject={Name: <AD-USER-ACCOUNT>; Domain:vmware.com}, groups=[{Name: AD-USERS-VMWARE; Domain:vmware.com}, {Name: SRM-Users; Domain:vmware.com}, {Name: AD-USERS-BROADCOM; Domain:vmware.com}, {Name: SystemConfiguration.Administrators; Domain:vsphere.local}, {Name: LicenseService.Administrators; Domain:vsphere.local}, {Name: Everyone; Domain:vsphere.local}], delegationChain=[], startTime=2025-02-11 15:29:39.865, endTime=2025-02-11 15:34:39.865, renewCount=0, delegableCount=0, isSolution=false, type=Saml_Bearer]


/var/log/vmware/sso/svcaccountmgmt.log:  

[YYYY-MM-DDTHH:MM:SS] INFO svcaccountmgmt[69:tomcat-http--32] [CorId=8d12a295-####-####-####-############ OpId=] [com.vmware.vcenter.svcaccountmgmt.vapi.setup.AuthzPermissionValidator] User vmware.com\\AD-USERS-VMWARE has required privileges [ServiceAccount.ManageAccount] to invoke API com.vmware.vcenter.svcaccountmgmt.service_account.create
[YYYY-MM-DDTHH:MM:SS] INFO svcaccountmgmt[69:tomcat-http--32] [CorId=8d12a295-####-####-####-############ OpId=] [com.vmware.vcenter.svcaccountmgmt.impl.ServiceAccount] Creating Service Account : com.vmware.vr-sa-########-####-####-####-############
[YYYY-MM-DDTHH:MM:SS] ERROR svcaccountmgmt[69:tomcat-http--32] [CorId=8d12a295-####-####-####-############ OpId=] [com.vmware.vcenter.svcaccountmgmt.impl.ServiceAccount] createServiceAccount: Got Directory Exception
[YYYY-MM-DDTHH:MM:SS] ERROR svcaccountmgmt[69:tomcat-http--32] [CorId=8d12a295-####-####-####-############ OpId=] [com.vmware.vcenter.svcaccountmgmt.impl.DirectoryError] Entry already exists, VMware directory error[9706]

Environment

  • VMware vCenter Server 8
  • vSphere Replication less than version 9.0.3
  • VMware Live Site Recovery less than version 9.0.3

Cause

The vSphere Replication (VR) configuration incorrectly attempts to create internal solution users using the domain associated with the provided administrator account instead of the default vCenter domain. When a non-default domain is provided, the process fails to locate or create the required service account.

Resolution

Non-default domain will be supported in VLR 9.0.3, shipping with VCF 9.0.

Workaround:

  1. For Versions of vSphere Replication and VMware Live Site Recovery lower than 9.0.3, use an administrator account belonging to the default vCenter domain (e.g., administrator@vsphere.local).
    • If the default domain is a custom domain (e.g., xyz.local), ensure you use the @xyz.local suffix.
  2. For Versions of vSphere Replication and VMware Live Site Recovery 9.0.3 or greater, verify that the AD account is a member of the vCenter Single Sign-On administrator group on the vCenter instance. Refer Configure the VMware Live Recovery Appliance to Connect to a vCenter instance