Error: "Registration failed at [Workload Domain Name] - NSX-T due to an issue with the identity broker's reachability or a failure to create authentication source" during VCF 9.1 upgrade
search cancel

Error: "Registration failed at [Workload Domain Name] - NSX-T due to an issue with the identity broker's reachability or a failure to create authentication source" during VCF 9.1 upgrade

book

Article ID: 446530

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

  • An upgrade from VMware Cloud Foundation (VCF) 9.0.2 to 9.1 results in a Single Sign-On (SSO) registration failure for the NSX Manager component.

  • The VCF Operations interface displays the following error: "Registration failed at [Workload Domain Name] - NSX-T due to an issue with the identity broker's reachability or a failure to create authentication source".

  • This failure prevents the integration of the workload domain into the unified Identity Broker framework resulting in functional impact of administrative access and security management functions.

Environment

VMware Cloud Foundation 9.x

Cause

Restrictive firewall rules on the NSX Manager block communication from the VCF Operations Identity Broker cluster. This network isolation prevents the establishment of a secure trust relationship and API reachability required for VCF SSO configuration over port 443.

Resolution

Establish network reachability between the Identity Broker and the NSX Manager by modifying network firewall configurations to allow bidirectional traffic between the VCF Operations cluster and the NSX Manager on port 443.

  1. Within the NSX Manager, navigate to Security > Distributed Firewall > Category Specific Rules.
  2. Enable the necessary rules to permit required traffic.
  3. Restart the registration task within the VCF Operations interface.