Invalid Credentials on login to vCenter when LDAP(S) is using a DNS alias of the Active Directory Domain
search cancel

Invalid Credentials on login to vCenter when LDAP(S) is using a DNS alias of the Active Directory Domain

book

Article ID: 443344

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

  • vCenter server is configured for LDAP(S) authentication

  • vCenter -> Administration -> Single Sign On -> Configuration -> Identity Source -> Active Directory over LDAP -> Domain Name configured for a DNS FQDN alias of the Active Directory Domain.



  • /var/log/vmware/sso/websso.log errors:

Failed to find user@alias_fqdn_of_domain

Environment

vCenter Server 8.x

Cause

LDAPS is configured to use a DNS FQDN alias of the Active Directory domain and cannot properly search Active Directory for users.

Resolution

Reconfigure the LDAPS 'Domain name' configuration to use the Active Directory FQDN domain name instead of the aliased DNS FQDN of the Active Directory domain.

Additional Information

See Active Directory over LDAP Identity Source Settings and Configuring a vCenter Single Sign-On Identity Source using LDAP with SSL (LDAPS).