Authentication failure to Onpremise vCenter server alert post VLCR upgrade to 9.0.0.11
search cancel

Authentication failure to Onpremise vCenter server alert post VLCR upgrade to 9.0.0.11

book

Article ID: 424714

calendar_today

Updated On:

Products

VMware Live Recovery

Issue/Introduction

  • These alerts are seen after the VLCR instance upgrade to latest version 9.0.0.11.

Or 

  • You may see below alert 

vCenter X.X.X.X is authenticated through a restricted vCenter user. This type of registration is DEPRECATED. Upgrading to service account is recommended.

  • You will also see alerts for the connectors transitioning from GOOD to CRITICAL "Failed to update connector(s) 'connector name' on site 'site name' with service account credentials. Make sure connectors are up and running"

  • Rebooting the connector or re-deploying the connector will not resolve the issue. 

  • If the existing vc extension/solution user certificate is expired prior to upgrade, upgrade to service account will fail post upgrade and may notice missing VMs from Tag based Protection Groups.

 

Environment

VMware Live Cyber Recovery 9.0.0.11

Cause

In VCF 9, solution users are deprecated in favor of service accounts. In 9.0.0.11, vCenter registration will switch from vc extension/solution user (cert based) to service accounts (username/password). All new vCenter registrations will automatically use service accounts. Upgrading to 9.0.0.11 will automatically replace the use of vc extension/solution user with service accounts. The secret (i.e. password) associated with each service account get refreshed periodically(~3 months).Existing vCenters previously registered with custom account credentials will continue to work as is but will need manual upgrade to service accounts.If the existing vc extension/solution user certificate is expired prior to upgrade, upgrade to service account will fail post upgrade and will cause replications to fail as well.

Resolution

Scenario 1) : Using vCenter extension/solution user for vCenter registration 

 
  • If the solution user certificate is expired, upgrade to sevice account will fail and and there will be a prompt in the VLCR dashboard to reregister the vCenter.
  • Select "Reregister vCenter" in menu option in the vCenter tile as shown below 
Scenario 2) : Using custom/restricted user for vCenter registration 
  • We will not be able to upgrade to service accounts after upgrade, however the replications will continue to run successfully. The dashboard will prompt a warning as “vCenter X.X.X.X is authenticated through a restricted vCenter user. This type of registration is DEPRECATED. Upgrading to service account is recommended.”.
  • Select the “Upgrade to service account” option for each vCenter which is registered with the custom user as shown below

    Additional Information

    • This issue is only observed during the upgrade to 9.0.0.11. Once we upgrade to the service account we will never see this issue and no actions would be required further.