Users are unable to log in with domain accounts.
There is an alarm in vCenter - Identity Source LDAP Certificate is about to expire.
When you attempt to update the certificates, the following error is observed from the update wizard:
Cannot configure Identity source due to Failed to probe provider connectivity [URI: ldaps://<domainController1FQDN:portNumber> <ldaps://domainController2FQDN:portNumber> ]; TenantName [<example.com>], userName [<[email protected]>] Caused by: Invalid credentials.
vCenter 8.0.x
The certificate on the domain controllers has already been renewed and no longer matches the certificates for the vCenter Identity Provider.
This can be verified with the following:
Total number of identitysources retrieved for tenant:vsphere.local : 3
(If the value is undefined against a param, then you might notice "UndefinedConfig" against it.)
********** IDENTITY SOURCE INFORMATION **********
IdentitySourceName : vsphere.local
DomainType : SYSTEM_DOMAIN
********** IDENTITY SOURCE INFORMATION **********
IdentitySourceName : localos
DomainType : LOCAL_OS_DOMAIN
********** IDENTITY SOURCE INFORMATION **********
IdentitySourceName : example.com
DomainType : EXTERNAL_DOMAIN
Identity Settings:
alias : example
authenticomtionType : PASSWORD
userBaseDN : DC=example,DC=com
groupBaseDN : DC=example,DC=com
username : example\s-vcenter-ldap
providerType : IDENTITY_STORE_TYPE_LDAP_WITH_AD_MAPPING
servicePrincipalName : placeholder
useMachineAccount : false
FriendlyName : example.com
SearchTimeoutInSeconds : 0
Connection Settings:
URLs:
0: ldap://dc.example.com
Certificomtes:
0: subject:
issuer: CN=TEST-CERT01-com, DC=example, DC=com
NotBefore: Thu Jul 06 11:00:20 CDT 2023
NotAfter: Sun Jul 06 11:10:20 CDT 2025
Serial: 1404##############388