ELM vCenter won't let authenticate users for login after removing vCHA
search cancel

ELM vCenter won't let authenticate users for login after removing vCHA

book

Article ID: 437520

calendar_today

Updated On:

Products

VMware vCenter Server 8.0

Issue/Introduction

1.Users are unable to authenticate to the ELM vCenter Server via SSO following the removal of vCenter High Availability (vCHA). The login page loads, but authentication attempts fail with a connection timeout

2. vsphere_client_virgo log indicated SSO Read timed out:

com.vmware.vim.vmomi.client.exception.ConnectionException: http://localhost:1080/.../sso-adminserver/sdk/vsphere.local invocation failed with "java.net.SocketTimeoutException: Read timed out"

3.The perfcharts service failed to initialize within the expected timeout period.

4.Websso log indicated a failure to retrieve the User Principal Name (UPN) suffixes via the AD-over-LDAP provider:

Failed to retrieve upnUurfixed in AD over LDAP : Can't contact LDAP server

Environment

VMware vCenter Sever 8.0.3

Resolution

1.Create snapshot for ELM vCenter refer to KB313886

2.Manually transition the `vmdir` state from read-only to normal using `vdcadmintool` refer to KB418432

3.Update `/etc/resolv.conf` with valid, reachable DNS server entries.

4.Restart all vCenter services to clear stale tokens and initialize services with the corrected network path.