vIDM users can login directly to NSX and bypass vIDM
search cancel

vIDM users can login directly to NSX and bypass vIDM

book

Article ID: 390444

calendar_today

Updated On:

Products

VMware NSX VMware Cloud Foundation

Issue/Introduction

  • VMware Identity Manager (vIDM) is configured in NSX.
  • NSX displays the local login page instead of the vIDM login page by default.
  • Entering vIDM credentials in the NSX local login allows the user to authenticate and bypass vIDM.

Environment

VMware NSX

 

Cause

The correct NSX UI authorization workflow is to 'Sign in with vIDM' from the NSX login page and vIDM will then redirect to NSX:

  • NSX 4.2.1 ensures NSX displays the local login page instead of the vIDM login page by default for this purpose.

 

However, entering vIDM credentials in the NSX local login should NOT allow users to authenticate and bypass vIDM:

  • NSX 4.2.4 and VCF 9.0.0 includes a fix to prevent local NSX login requests from bypasssing vIDM.

Resolution

This issue is resolved in VMware NSX 4.2.4 and VCF 9.0.0, available at Broadcom downloads.

If you are having difficulty finding and downloading software, please review the Download Broadcom products and software KB.

 

Workaround
The correct NSX UI authorization workflow to follows is below:

  1. Click the "Sign in with vIDM" link on the NSX UI login page (do not enter credentials into the local login fields):


  2. Log into the vIDM server with a vIDM user account.
  3. vIDM server redirects the browser back to NSX.

Additional Information

NSX UI redirects to the standard NSX login page instead of redirecting to the vIDM login page   
Error: "Your login attempt was not successful" when using vIDM user account in NSX
Logging in to NSX Manager