After rebooted the SRM appliance, the following error message appeared on Site recovery GUI.
Unable to retrieve pairs from extension server at https://SRM FQDN:443/drserver/vcdr/vmomi/sdk. Unable to connect to Site recovery Manager Server at https://SRM FQDN:443/drserver/vcdr/vmomi/sdk Reason: Unable to downlaod
versions file from Site Recovery Manager Server at https://SRM FQDN:443/drserver/vcdr/vmomi/sdk. HTTP responce; HTTP/1.1 503 Service Unavailable
vCenter Serer 7.0.X
vCenters use Enhanced Linked Mode.
Site Recovery Manager 8.X
Group membership information for SRM solution users was lost in the vmdir of vCenter .
To check the lost status of group membership information from logs
SRM Log
2025-01-21T10:54:37.806+09:00 info vmware-dr[00940] [SRM@6876 sub=SsoClient]
Successfully acquired token: SamlToken [subject={Name: SRM-XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX; Domain:vsphere.local},
groups=[{Name: Everyone; Domain:vsphere.local}], ← only one
delegationChain=[], startTime=2025-01-21 01:54:37.780, expirationTime=2025-01-21 09:54:37.780, renewable=false, delegable=false, isSolution=true,confirmationType=1]ger Server at https://SRM FQDN:443/drserver/vcdr/vmomi/sdk. HTTP responce; HTTP/1.1 503 Service Unavailable
Correct and expected group membership information is like the followings.
2025-01-21T12:06:36.167+09:00 info vmware-dr[03838] [SRM@6876 sub=SsoClient opID=d73c9bdf-fd2d-48bd-9f4d-1448b5a683f8-tryFederatedSso]
Successfully acquired token: SamlToken [subject={Name: SRM-XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX; Domain:vsphere.local},
groups=[{Name: Administrators; Domain:vsphere.local},
{Name: SolutionUsers; Domain:vsphere.local},
{Name: LicenseService.Administrators; Domain:vsphere.local},
{Name: SystemConfiguration.Administrators; Domain:vsphere.local},
{Name: Everyone; Domain:vsphere.local}],
delegationChain=[], startTime=2025-01-21 03:06:36.136, expirationTime=2025-01-21 11:06:36.136, renewable=false, delegable=false, isSolution=true,confirmationType=1]
vCenter vpxd log
2024-10-05T05:43:07.880+09:00 info vpxd[17273] [Originator@6876 sub=User opID=66f6bdd0:3767-fb]
SSO Login > User: 'VSPHERE.LOCAL\SRM-XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX',
Groups: '{Name: Everyone; Domain:vsphere.local} ', <-- only one
DelegationChain: 'vsphere.local\vpxd-extension-YYYYYY-YYYY-YYYY-YYYY-YYYYYYYYYYY '
Correct and expected group membership information is like the followings.
2025-01-22T11:53:32.751+09:00 info vpxd[17708] [Originator@6876 sub=User opID=ba151bd7-a12f-4e07-9cc3-037ef8fa8b7d-f3]
SSO Login > User: 'VSPHERE.LOCAL\SRM-XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX',
Groups: '{Name: Administrators; Domain:vsphere.local}
{Name: SolutionUsers; Domain:vsphere.local}
{Name: LicenseService.Administrators; Domain:vsphere.local}
{Name: SystemConfiguration.Administrators; Domain:vsphere.local}
{Name: Everyone; Domain:vsphere.local} ',
DelegationChain: 'vsphere.local\vpxd-extension-YYYYYY-YYYY-YYYY-YYYY-YYYYYYYYYYY '
To check the lost status of group membership information by command into vCenter
1. SSH login vCenter
2. /usr/lib/vmware-vmafd/bin/dir-cli group list --name Administrators
ex.
/usr/lib/vmware-vmafd/bin/dir-cli group list --name Administrators
Enter password for [email protected]: <- vCenter login password
...
CN=SRM-XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXX,cn=ServicePrincipals,dc=vsphere,dc=local
SRM solution user ID is displayed in normal case.
In the case using vCenter Enhanced Linked Mode between the protected site and DR site, two SRM Solution User IDs are displayed.
If SRM Solution User ID is not listed, the group memberships have been lost for SRM solution user.
Both reconfigure SRM and reconnect the site pair are required.
1. Reconfigure SRM in SRM Appliance Management Interface
2. Reconnect Site Pair after reconfigure SRM.
The cause of the loss of group membership for the SRM Solution User in the vmdir needs to be investigated in vCenter Server side.