Error: STS connection string is incorrect (ldap://:389) in VMware vCenter Server
search cancel

Error: STS connection string is incorrect (ldap://:389) in VMware vCenter Server

book

Article ID: 399834

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

Running the vSphere Diagnostic Tool (VDT) on a vCenter Server identifies an IDENTITY SOURCE CHECKS failure. This commonly occurs during pre-upgrade validations for vCenter 7.x and 8.x or following the decommission of a vCenter node in an Enhanced Linked Mode (ELM) environment. If not corrected, this stale entry prevents services from starting or causes authentication issues when the incorrectly referenced node is offline.

  • IDENTITY SOURCE CHECKS [FAIL] STS connection string is incorrect (ldap://<fqdn_of_vCenter_Server>:389)
  • MISCONFIG status appearing in vCert tool results for STS ConnectionStrings.
  • Error appears during vCenter 7.x to 8.x upgrade pre-checks.
  • vCenter services such as vapi-endpoint and vpxd-svcs fail to start with "Unexpected status code: 404".
  • Logs show: HEALTH ORANGE Failed to retrieve SSO settings from Lookup Service.

Environment

  • vCenter 7.x
  • vCenter 8.x

Cause

The vmwSTSConnectionStrings attribute fails to revert to the default value of ldap://localhost:389 after a partner node is decommissioned, leaving a stale entry pointing to a non-existent FQDN or IP

Resolution

This issue is resolved in vCenter Server 8.0 U3. To download this release, see Download Broadcom products and software.

To manually correct the vmwSTSConnectionStrings attribute to the default setting, follow these steps:

Download the fix_sts_attrs.py script attached to vCenter services vapi-endpoint and vpxd-svcs fail to start with "Unexpected status code: 404" (323195).

  1. Follow the documented procedures in KB323195 to execute the script.
  2. Set the STS connection string to ldap://localhost:389.
  3. Verify the resolution by re-running the vSphere Diagnostic Tool (VDT)

Note: To receive updates on this issue, subscribe to this article. See How to subscribe to a Knowledge Article

Additional Information

If additional assistance is required, see Contact Support. Scroll to the bottom of the page and click on your respective region.