Password rotation tasks complete successfully, but the account status remains "Disconnected."
VMware Cloud Foundation 5.2.x
VMware Cloud Foundation 9.x
SDDC Manager 5.2.x
SDDC Manager 9.x
VMware vCenter Server 8.x
vCenter 9.x
A password validity value of 0 returned by the vCenter API caused the SDDC Manager to incorrectly display the service account expiry date as 1970-01-01.
Broadcom Engineering team is aware of the issue and working towards the fix in upcoming release. In the meantime, apply the following workaround:
Validate the service account expiry:
SSH to the SDDC Manager with vcf and elevate to root using su.
Access the database, and execute the following select query:
psql -h localhost -U postgres
\c operationsmanager
select * from passwordmanager.credential_expiry where resource_type='VCENTER';
Note: Verify the output against the example below. If it does not match, run \x to enable "Expanded display" and repeat the query.
Modify the service account expiry utilizing either of the methods detailed below prior to re-attempting the password rotation.
Log in to vCenter Server.
Navigate to Menu > Administration > Configuration > Local Accounts.
Update the Maximum Lifetime setting under password policy to 9999 days.
Or
SSH into the vCenter with the root user and run the following command: /usr/lib/vmware-vmafd/bin/dir-cli user modify --account svcAccountUsername --password-never-expires
Note: When entering the svcAccountUsername do not include the domain name ([email protected]).
If alarms (banners) are still triggered related to the VC disconnected state for SDDC manager client and/or VC vSphere client, even after the SDDC manager shows the VCSA as being connected, please wait for the daily auto-inventory sync at 0300 local server time. The alerts should auto clear.
If the SDDC UI still shows 1970-01-01 after setting the password to never expire via dir-cli, update the credential_expiry table using the commands below.
Note: Take a snapshot of the SDDC manager VM prior to any changes.
psql -U postgres -h localhost
\c operationsmanager
update passwordmanager.credential_expiry set expiry_date='2299-01-01 01:00:20.233077' where id='<id>'; If the UI (vSphere Client, SDDC Manager) does not immediately reflect the changes, a synchronization is likely pending. Wait for the daily auto-inventory sync at 0300 local server time.
As an alternative, password expiration details can be retrieved manually through the SDDC Manager API Explorer.
Log in to SDDC Manager UI.
Navigate to Developer Center > API Explorer > Credentials > POST /vi/credentials/expirations (Reference: Get Password Expiration).
Under the value for body enter the below:
{ "credentialIds": [ "" ], "domainName": "", "resourceType":"VCENTER" }For further assistance Contact Broadcom support.