Active Directory users randomly unable to authenticate to vCenter Server
search cancel

Active Directory users randomly unable to authenticate to vCenter Server

book

Article ID: 424190

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

The Active Directory Identity Source is pointed to the root domain, or using a load balancer having several domain controllers available to choose from.

Failed to bind errors found at random intervals in /var/log/vmware/sso/websso.log similar to the following:

YYYY-MM-DDTHH:MM:SSZ WARN websso[##:tomcat-http--##] [CorId=<unique ID>] [com.vmware.identity.interop.ldap.LdapErrorChecker] Error received by LDAP client: com.vmware.identity.interop.ldap.OpenLdapClientLibrary, error code: 49
YYYY-MM-DDTHH:MM:SSZ WARN websso[##:tomcat-http--##] [CorId=<unique ID>] [com.vmware.identity.interop.ldap.LdapErrorChecker] Error received by LDAP client: com.vmware.identity.interop.ldap.OpenLdapClientLibrary, error code: -5

Errors coming from the domain controllers shown in /var/log/vmware/sso/ssoAdminServer.log similar to the following:

YYYY-MM-DDTHH:MM:SSZ WARN ssoAdminServer[###:pool-#-thread-##] [OpId=<unique ID>] [com.vmware.identity.interop.ldap.LdapErrorChecker] Error received by LDAP client: com.vmware.identity.interop.ldap.OpenLdapClientLibrary, error code: -5
YYYY-MM-DDTHH:MM:SSZ WARN ssoAdminServer[###:pool-#-thread-##] [OpId=<unique ID>] [com.vmware.identity.idm.server.ServerUtils] cannot bind connection: [ldap://<AD Domain>, <vCenter Domain>]
YYYY-MM-DDTHH:MM:SSZ WARN ssoAdminServer[###:pool-#-thread-##] [OpId=<unique ID>] [com.vmware.identity.idm.server.ServerUtils] cannot establish ldap connection with URI: [ldap://<AD Domain>] because [com.vmware.identity.interop.ldap.TimeoutLdapException] with reason [Timed out] therefore will try to attempt to use secondary URIs, if applicable

 

Eventually, authentications for Active Directory users will succeed.

Environment

VMware vCenter Server 8.x

Cause

One or more of the domain controllers is not working correctly for authentication through vCenter Server.  When this domain controller is selected at random by vCenter Server or by the load balancer, the authentication fails.  Investigate the domain controllers being used to identify the cause of the failure.

Resolution

 Reconfigure the identity source to use only known/good domain controllers.

Additional Information

For issues where Read-only domain controllers are found:

For issues where the ldap connection fails to bind citing "invalid credentials in the logging"