Running the vSphere Diagnostic Tool (VDT) on a vCenter Server identifies an IDENTITY SOURCE CHECKS failure. This commonly occurs during pre-upgrade validations for vCenter 7.x and 8.x or following the decommission of a vCenter node in an Enhanced Linked Mode (ELM) environment. If not corrected, this stale entry prevents services from starting or causes authentication issues when the incorrectly referenced node is offline.
IDENTITY SOURCE CHECKS [FAIL] STS connection string is incorrect (ldap://<fqdn_of_vCenter_Server>:389)vapi-endpoint and vpxd-svcs fail to start with "Unexpected status code: 404".HEALTH ORANGE Failed to retrieve SSO settings from Lookup Service.The vmwSTSConnectionStrings attribute fails to revert to the default value of ldap://localhost:389 after a partner node is decommissioned, leaving a stale entry pointing to a non-existent FQDN or IP
This issue is resolved in vCenter Server 8.0 U3. To download this release, see Download Broadcom products and software.
To manually correct the vmwSTSConnectionStrings attribute to the default setting, follow these steps:
Download the fix_sts_attrs.py script attached to vCenter services vapi-endpoint and vpxd-svcs fail to start with "Unexpected status code: 404" (323195).
Note: To receive updates on this issue, subscribe to this article. See How to subscribe to a Knowledge Article
If additional assistance is required, see Contact Support. Scroll to the bottom of the page and click on your respective region.