"Identity broker is unhealthy" Reported During Single Sign-On Configuration in VCF Operations 9.x
search cancel

"Identity broker is unhealthy" Reported During Single Sign-On Configuration in VCF Operations 9.x

book

Article ID: 441948

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

  • Attempting to configure Single Sign-On (SSO) in VCF Operations (VCF Ops) 9.x, the system reports the error: "Identity broker is unhealthy. View additional details in the 'Alerts' section under 'Infrastructure Operations'"

VCF Ops -> Fleet Management -> Identity & Access -> VCF Instances -> Select Instance

  • Configuring Identity Provider may return the failure as "XML metadata is invalid! Reason: Could not resolve endpoint type EXTERNAL_VIDB for adapter task VALIDATE_SAML_METADATA"

Environment

Environment VCF Operations 9.x, External VIDB deployment

Cause

This issue is triggered by a version discrepancy, specifically when the VMware Identity Broker (VIDB) and the Fleet Manager are operating on different patch levels.

Resolution

  1. Verify the current version of the Fleet Manager by navigating to VCF Ops -> Fleet Management -> Identity & Access -> VCF Instances

  2. Compare the version of the VIDB nodes against the Fleet Manager version under Lifecycle -> Components

  3. If a mismatch exists, patch the VIDB to match the exact patch version of the Fleet Manager. Refer to Updating or Patching Individual VCF Core Components for detailed patching procedure