Import of Users and Groups Fails Due to Invalid LDAP Bind Credentials
search cancel

Import of Users and Groups Fails Due to Invalid LDAP Bind Credentials

book

Article ID: 411319

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite) VCF Automation

Issue/Introduction

Importing Users and Groups from a custom LDAP source failed with the error: [ <User_UUID> ] LDAP context not initialized. Error connecting to LDAP.
Initial LDAP connectivity tests passed, but user/group import from the Identity Source did not proceed.

Environment

VCF Automation

VCF vIDB

 

Cause

The LDAP bind account (Username) was configured with incorrect credentials.

LDAP error code 49 directly indicates an authentication failure caused by invalid username or password. This aligns with the observed authentication exception during sync
Sync fails with error 'javax.naming.AuthenticationException:[LDAP:error code 49 - Invalid Credentials]

  • LDAP error code 49 indicates an authentication failure due to invalid username or password.

Resolution

Update the bind account password in the Custom LDAP configuration with the correct password for the (Username) user and reinitiate the sync.

Additional Information:

  • LDAP error code 49 indicates an authentication failure due to invalid username or password.

  • After correcting the bind password and saving the configuration, the synchronization completed successfully, and user/group imports resumed normal operation.

Additional Information

How to check Sync 

For a complete VCF 9.0 environment, there is only one vIDB instance (single or clustered).
To check and synchronize settings and logs:

Login to Ops
-> Fleet Management
    -> Identity & Access
    -> VCF Management 
        -> Automation -> Select the identity source -> Edit 
        -> The last options are 'Sync Settings' - Default is once per week
        -> Sync log - Will list all the changes

Reference doc: https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-0/fleet-management/what-is/setting-up-sso/cofigure-vmware-cloud-foundation-identity-provider/configure-vmware-cloud-foundation-identity-provider-for-ad-ldap(2)/managing-ad-over-ldap.html