The vcenter servers are in enhanced linked mode
Site Recovery Manager (SRM) or vSphere Replication (VR) appliance status reports as Not Configured.
Site Recovery client reports: Unable to retrieve pairs from extension server
Attempts to reconfigure the vSphere Replication or SRM appliance fail with: sso.fault.InternalFault or Failed to register VRMS or "Failed Host 'vc_hostname' could not be contacted."
Operation Failed Host 'vc_hostname' could not be contacted.Operation ID: e70dedc0-8b9e-45a0-add3-bfdc26a1d165
Appliance logs (drconfig.log) contain:
2025-07-11T11:19:09.330+05:30 error drconfig[01176] [SRM@6876 sub=ConfigureVrmsOp opID=e6e28641-aa40-4864-8825-bbc61837a636-configure:29d2] command:................................--> stderr:--> /usr/lib/python3.10/getpass.py:91: GetPassWarning: Can not control echo on the terminal.--> Unhandled exception--> (sso.fault.InternalFault) 2025-07-11T11:19:09.331+05:30 error drconfig[01176] [SRM@6876 sub=ConfigureVrmsOp opID=e6e28641-aa40-4864-8825-bbc61837a636-configure:29d2] Operation failed--> (vmodl.fault.SystemError) {--> faultCause = (vmodl.MethodFault) null,--> faultMessage = <unset>,--> reason = "Failed to register VRMS."--> msg = ""--> }2025-07-11T11:14:47.470+05:30 warning drconfig[24595] [SRM@6876 sub=SupportBundleRequestHandler.HmsHealthHandler opID=812ec3ad] HMS Health err output:--> com.vmware.jvsl.sso.SsoException: com.vmware.vim.sso.client.exception.AuthenticationFailedException: Provided credentials are not valid.
--> Caused by: com.vmware.vim.sso.client.exception.AuthenticationFailedException: Provided credentials are not valid.
vmware-dr.log, an authentication failure regarding the Secure Token Service (STS) is recorded:2026-08-15T06:41:41.542+01:00 verbose vmware-dr[01741] [SRM@6876 sub=IO.Connection] Attempting connection; <resolver p:0x00007f02d8016f00, 'vc_hostname:443', next:<TCP '###.##.###.## : 443'>>, last e: 0(Success)2026-08-15T06:41:41.570+01:00 error vmware-dr[01746] [SRM@6876 sub=LocalSite.LocalStsServer.ConnHandler] Unable to retrieve token from STS:--> N9SsoClient27InvalidCredentialsExceptionE Authentication failed: Invalid credentials
2026-08-15T06:42:40.631+01:00 panic vmware-dr[01738] [SRM@6876 sub=Default] Application error: N7Vmacore9ExceptionE Failed to connect to remote services on ["vc_hostname"]--> [context]zKq7AVECAAQAACoIZgERdm13YXJlLWRyAAD9BVBsaWJ2bWFjb3JlLnNvAADy/CQA/HwiAMrzGwFQewJ2bXdhcmUtZHIAATHwCwFhyAwCLsUJbGliZHItYXV0aG9yaXphdGlvbi5zbwABArALAYOFDAHulgsBIUQDASvJDAMmZgtsaWJkci12bWFjb3JlLnNvAAGA+gIECn8CbGliYy5zby42AAHt/AI=[/context]--> [backtrace begin] product: VMware vCenter Site Recovery Manager, version: 9.0.0, build: build-23463978, tag: vmware-dr, cpu: x86_64, os: linux, buildType: release--> backtrace[00] libvmacore.so[0x005005FD]--> backtrace[01] libvmacore.so[0x0024FCF2]: Vmacore::System::Stacktrace::CaptureWork(unsigned int)--> backtrace[02] libvmacore.so[0x00227CFC]: Vmacore::System::SystemFactory::CreateQuickBacktrace(Vmacore::Ref<Vmacore::System::Backtrace>&)--> backtrace[03] libvmacore.so[0x001BF3CA]: Vmacore::Throwable::Throwable(std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > const&)--> backtrace[04] vmware-dr[0x00027B50]--> backtrace[05] vmware-dr[0x000BF031]--> backtrace[06] vmware-dr[0x000CC861]--> backtrace[07] libdr-authorization.so[0x0009C52E]: Dr::Authorize::EntityWithPermissionsLifetimeMixin::_Activate(bool)--> backtrace[08] vmware-dr[0x000BB002]--> backtrace[09] vmware-dr[0x000C8583]--> backtrace[10] vmware-dr[0x000B96EE]--> backtrace[11] vmware-dr[0x00034421]--> backtrace[12] vmware-dr[0x000CC92B]--> backtrace[13] libdr-vmacore.so[0x000B6626]: Dr::DrApp::Run(std::function<int ()> const&)--> backtrace[14] vmware-dr[0x0002FA80]--> backtrace[15] libc.so.6[0x00027F0A]--> backtrace[16] vmware-dr[0x0002FCED]--> [backtrace end]
vmware-identity-sts.log, invalid credentials are confirmed for the Site Recovery Manager solution user:2026-08-17T03:16:04.423Z WARN sts[50:tomcat-http--4] [CorId=3b6c6603-d6b5-40d3-a429-ec3a13849821] [com.vmware.identity.interop.ldap.LdapErrorChecker] Error received by LDAP client: com.vmware.identity.interop.ldap.OpenLdapClientLibrary, error code: 492026-08-17T03:16:04.423Z WARN sts[50:tomcat-http--4] [CorId=3b6c6603-d6b5-40d3-a429-ec3a13849821] [com.vmware.identity.idm.server.ServerUtils] cannot bind connection: [ldap://vc_hostname:389, SRM-404eabe4-8111-4e37-906e-#########@vsphere.local]2026-08-17T03:16:04.423Z ERROR sts[50:tomcat-http--4] [CorId=3b6c6603-d6b5-40d3-a429-ec3a13849821] [com.vmware.identity.idm.server.ServerUtils] cannot establish ldap connection with URI: [ldap://vc_hostname:389] because [Invalid credentials] therefore will not attempt to use any secondary URIs2026-08-17T03:16:04.431Z ERROR sts[50:tomcat-http--4] [CorId=3b6c6603-d6b5-40d3-a429-ec3a13849821] [com.vmware.identity.idm.server.IdentityManager] Failed to authenticate principal [[email protected]]. Login failedjavax.security.auth.login.LoginException: Login failed at com.vmware.identity.idm.server.provider.vmwdirectory.VMwareDirectoryProvider.authenticate(VMwareDirectoryProvider.java:428) ~[libvmware-identity-idm-server.jar:?]
(vmdir) on the vCenter Server has entered a "Read only" state. This prevents solution users (like the SRM or VRMS service accounts) from updating their credentials or state, leading to authentication and connectivity failures.vmdird-syslog.log contains: Error (LDAP_UNWILLING_TO_PERFORM(53)) Message (Server in read-only mode)2025-07-11T06:00:02 err vmdird t@139743522182912: VmDirSendLdapResult: Request (Modify), Error (LDAP_UNWILLING_TO_PERFORM(53)), Message (Server in read-only mode), (0) socket (127.0.0.1)
/usr/lib/vmware-vmdir/bin/vdcadmintool
Please select:0. exit1. Test LDAP connectivity2. Force start replication cycle3. Reset account password4. Set log level and mask5. Set vmdir state6. Get vmdir state7. Get vmdir log level and mask
6
VmDir State is - Read only