NSX Manager Password Expiration causing SDDC Manager Disconnections
search cancel

NSX Manager Password Expiration causing SDDC Manager Disconnections

book

Article ID: 426253

calendar_today

Updated On:

Products

VMware NSX VMware SDDC Manager / VCF Installer

Issue/Introduction

  • Multiple NSX accounts are displayed as disconnected in the SDDC Manager dashboard.
  • Root, Admin and Audit accounts are expired.
  • Attempts to remediate the passwords for these account using the SDDC Manager UI result in failures.
  • The NSX Manager UI displays error messages regarding the Audit account status.
  • When attempting to login directly per CLI to the NSX Manager node(s) as root, a prompt is shown, stating that the password for the account has expired and must be updated.

Environment

  • VMware Cloud Foundation 5.x
  • VMware Clound Foundation 9.x
  • VMware NSX

Cause

SDDC Manager uses these accounts to authenticate against and communicate with the NSX components. If the passwords of the accounts are expired, this communication will be disrupted, leading to the specific node to be disconnected from SDDC Manager.

Resolution

To resolve this issue, apply the following steps:

  1. Open an SSH session with each NSX Manager node and attempt to login as root with the existing password.
  2. When prompted to, reset the password.
  3. Log in as root with new root password created in step 2, and follow the steps outlined in the product documentation to reset the admin and audit passwords.
  4. Navigate to the Password Management section in the SDDC Manager UI on the left-hand side under SecurityPassword Management.
  5. Remediate the NSX nodes with the newly set passwords.
  6. Select the NSX Manager tab, then for each of the 3 accounts:
    • Find the user row (root, admin or audit) for the relevant NSX Manager cluster.
    • Click the vertical ellipsis (three dots) at the end of the row and select Remediate.
    • Enter the new root password that was manually set earlier on the node.
    • Click Remediate, then wait for the task to complete in the "Tasks" pane.
    • Repeat these steps for the other 2 accounts.
  7. If the Admin account remediation fails in SDDC Manager, see SDDC Manager unable to perform any password operations on NSX-T Managers, with the error: {"module_name":"common-services","error_message":"The credentials were incorrect or the account specified has been locked.","error_code":403} for additional steps.

Should the issue persist after these steps have been implemented, Contact Support.