Error: vCenter service account shows disconnected on 12/31/69 in SDDC Manager
search cancel

Error: vCenter service account shows disconnected on 12/31/69 in SDDC Manager

book

Article ID: 415429

calendar_today

Updated On:

Products

VMware SDDC Manager / VCF Installer

Issue/Introduction

  • vCenter service accounts display a "Disconnected" status in SDDC Manager password management with an incorrect expiration date of 12/31/69.

  • Password rotation tasks complete successfully, but the account status remains "Disconnected."

  • Unable to find the affected service accounts in the vCenter vSphere UI.

Environment

  • VMware Cloud Foundation 5.2.x 

  • VMware Cloud Foundation 9.x 

  • SDDC Manager 5.2.x

  • SDDC Manager 9.x

  • VMware vCenter Server 8.x

  • vCenter 9.x

Cause

A password validity value of 0 returned by the vCenter API caused the SDDC Manager to incorrectly display the service account expiry date as 1970-01-01.

Resolution

Broadcom Engineering team is aware of the issue and working towards the fix in upcoming release. In the meantime, apply the following workaround:

  1. Validate the service account expiry:

    1. SSH to the SDDC Manager with vcf and elevate to root using su.

    2. Access the database, and execute the following select query:

      1. psql -h localhost -U postgres

      2. \c operationsmanager

      3. select * from passwordmanager.credential_expiry where resource_type='VCENTER';

        Note: Verify the output against the example below. If it does not match, run \x to enable "Expanded display" and repeat the query.

  2. Modify the service account expiry utilizing either of the methods detailed below prior to re-attempting the password rotation.

    1. Log in to vCenter Server.

    2. Navigate to Menu > Administration > Configuration > Local Accounts.

    3. Update the Maximum Lifetime setting under password policy to 9999 days.

Or

    1. SSH into the vCenter with the root user and run the following command:  /usr/lib/vmware-vmafd/bin/dir-cli user modify --account svcAccountUsername --password-never-expires

      Note: When entering the svcAccountUsername do not include the domain name ([email protected]).

 

If alarms (banners) are still triggered related to the VC disconnected state for SDDC manager client and/or VC vSphere client, even after the SDDC manager shows the VCSA as being connected, please wait for the daily auto-inventory sync at 0300 local server time. The alerts should auto clear.

Additional Information

If the SDDC UI still shows 1970-01-01 after setting the password to never expire via dir-cli, update the credential_expiry table using the commands below.

Note: Take a snapshot of the SDDC manager VM prior to any changes.

  1. psql -U postgres -h localhost

  2. \c operationsmanager

  3. update passwordmanager.credential_expiry set expiry_date='2299-01-01 01:00:20.233077' where id='<id>';  

If the UI (vSphere Client, SDDC Manager) does not immediately reflect the changes, a synchronization is likely pending. Wait for the daily auto-inventory sync at 0300 local server time.

  1. As an alternative, password expiration details can be retrieved manually through the SDDC Manager API Explorer.

    1. Log in to SDDC Manager UI.

    2. Navigate to Developer Center > API Explorer > Credentials > POST /vi/credentials/expirations (Reference: Get Password Expiration).

    3. Under the value for body enter the below:

      {
          "credentialIds": [ "" ],
          "domainName": "",
          "resourceType":"VCENTER"   
      }

For further assistance Contact Broadcom support.