/var/log/vmware/sso/websso.log shows below errorsYYYY-MM-DDThh:mm:ss INFO websso[82:tomcat-http--46] [CorId=99c27465-d4b1-4978-a63b-108d98975b57] [com.vmware.identity.samlservice.impl.ExternalIdpProvider] Got exception (sleeping before retry)java.lang.Exception: Could not get Saml HOK token for solution user machineYYYY-MM-DDThh:mm:ss INFO websso[82:tomcat-http--46] [CorId=99c27465-d4b1-4978-a63b-108d98975b57] [com.vmware.identity.saml.impl.TokenLifetimeRemediator] There is a HoK confirmation certificate with end time: YYYY-MM-DDThh:mm:ss.000+0000YYYY-MM-DDThh:mm:ss ERROR websso[82:tomcat-http--46] [CorId=99c27465-d4b1-4978-a63b-108d98975b57] [com.vmware.identity.providers.SolutionUserHokTokenProviderImpl] Unable to get SAML HOK token for machine solution userYYYY-MM-DDThh:mm:ss ERROR websso[82:tomcat-http--46] [CorId=99c27465-d4b1-4978-a63b-108d98975b57] [com.vmware.identity.SsoController] Exception while processing external IDP request com.vmware.identity.samlservice.ExtIdpNotFoundException: Exception while processing External login request
/var/log/vmware/sso/vmware-identity-sts.log shows below errorsYYYY-MM-DDThh:mm:ss INFO sts[70:tomcat-http--34] [CorId=8abef7bf-051c-4ff0-a226-080fec172ead] [com.vmware.identity.sts.InvalidCredentialsException] Censored exception com.vmware.identity.sts.InvalidCredentialsException: Solution user cert is not valid.
The Solution User and Machine SSL certificates on the vCenter Server are expired.
To the resolve this issue renew the certificates using vCert
Note: Take offline snapshots for vCenters in Enhance Linked mode before the certificate renewal.
For similar issues with different causes, refer to related KBs.