Unable to authenticate using the AD account in Aria Automation, vIDM or LCM.
search cancel

Unable to authenticate using the AD account in Aria Automation, vIDM or LCM.

book

Article ID: 406736

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

  • Able to connect to Aria Suite Lifecycle (LCM) and Aria Automation using the configadmin local account, however not able to connect to vIDM.
  • vIDM is unable to authenticate the AD accounts to any of the appliances. 
  • Able to communicate from vIDM to the AD Servers. 
  • Restarted the Horizon services running on vIDM but the issue still persists.

Environment

Aria Lifecycle
VMware Identity Manager

Cause

  • Failure in DNS resolution for the vIDM nodes. vIDM nodes are unable to resolve the FQDN of the vIDM load balancer
  • Failure in DNS resolution for Aria Suite Lifecycle. Aria Suite Lifecycle machine is also unable to resolve the FQDN of the vIDM load balancer.
  • Incorrect passwords for vIDM nodes in the Aria Suite Lifecycle locker.

Resolution

  1. Create snapshots for vIDM nodes and Aria suite lifecycle in the vCenter.

  2. Configure the vIDM appliances to use the new DNS servers: 

    Power off the vIDM nodes manually, following the steps from KB Graceful Shutdown and Power On of a VMware Identity Manager PostgreSQL cluster

    Note: While stopping the Postgres Services, if the following message is displayed: Authentication token is no longer valid; new one required
    You will need to follow the step from KB: Opensearch Service fails to start with 'Authentication token is no longer valid' message.

    Edit the DNS OVF properties to the correct values using the following KB as a guide: Network not found error or networking information gets reset to old entries after upgrading VMware Identity Manager or after applying patch"

  3. Configure the Aria suite lifecycle appliance to use the new DNS servers as per the doc: Change in DNS server

  4. Update the vIDM credentials in the Aria Suite Lifecycle locker.

  5.  Re-register the Aria Suite Lifecycle authentication provider as per the resolution of the following KB: Login to vRSLCM using domain account fails with "HTTP ERROR 401"

  6. Perform an Inventory Sync of the vIDM environment using Aria suite lifecycle.