Error: “Users search in VCF SSO failed” during VCF Operations Import
search cancel

Error: “Users search in VCF SSO failed” during VCF Operations Import

book

Article ID: 419960

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

Importing users or groups in VCF Operations under Access Control fails with the following error: “Users search in VCF SSO failed"

This occurs typically after a vIDB redeployment or when the vIDB certificate has been replaced.

Symptoms

  • Users encounter "Failed to login with VCF SSO service" at the login screen.
  • Under Access Control, searching for VCF SSO sources returns "Users search in VCF SSO failed."

Environment

VCF Operations 9.x
VMware Identity Broker

Cause

Single Sign-On integration for the VCF Operations appliance is invalidated in Fleet Management after a vIDB redeployment or certificate rotation. Without an active integration, the appliance cannot query the VCF Identity Broker.

Resolution

Note: Performing the actions outlined below will result in the loss of all existing configurations for imported users and groups.

Follow these steps to re-establish the trust and import users:

Part 1: Enable Single Sign-On (SSO) for VCF Operations

  1. Log in to the VCF Operations UI as a local admin: https://<FQDN>/ui
  2. Navigate to Fleet Management > Identity & Access.
  3. Select VCF Management > Operations appliance.
  4. Under Enable Single Sign-On, click Continue.
  5. Check the confirmation box in the Role Assignment Required dialog and click Continue.
  6. Select the VCF Identity Broker from the dropdown and click Configure.
  7. Confirm the second Role Assignment Required dialog and click Continue.

Part 2: Import Users/Groups

  1. Navigate to Administration > Control Panel > Access Control.
  2. Go to the User Accounts or User Groups tab.
  3. Click the ellipsis () next to Add and select Import from Source.
  4. Set Import From to VCF SSO.
  5. Search for the desired users/groups and click Finish.
  6. Select the imported user, click the ellipsis (), choose Edit, and assign the required roles.

Additional Information