VCF Adapter Instance Displays Warning Status and Fails with "Invalid username or password" in VCF Operations
search cancel

VCF Adapter Instance Displays Warning Status and Fails with "Invalid username or password" in VCF Operations

book

Article ID: 446874

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

  • VMware Cloud Foundation (VCF) cloud account integration fails within VCF Operations. The VCF adapter instance displays a "Warning" status.
  • A manual "Test Connection" fails with the following error: Invalid username or password. Ensure that the specified user credentials are correct and the user has required permissions to access the target vCenter as per the document.

  • Additionally, the /storage/log/vcops/log/analytics-<id>.log contains the following entry: Failed to create service accounts. SvcAccountsCreationResult is null.

Environment

VCF Operations 9.1

Cause

This issue occurs when the System Managed Credential fails to rotate automatically, resulting in synchronization drift. The automated service account permissions fail to propagate properly to the affected vCenters. The adapter attempts to authenticate using an outdated or expired password, causing the target vCenter or NSX manager to reject the connection.

Resolution

To resolve this issue, manually trigger a rotation of the system-managed credential from the VCF Operations UI to generate a fresh password and resynchronize the connection:

  1. Log in to the VCF Operations UI as an administrator.

  2. Navigate to Administration > Integrations in the left panel.

  3. Select the Account tab.

  4. Expand the VMware Cloud Foundation adapter box, then expand the VCF Instance, followed by the specific domain (e.g., Management or Workload).

  5. Click Edit (or the vertical ellipsis) next to the failing vCenter adapter.

  6. Verify that the System Managed Credential checkbox is selected.

  7. Click the Rotate button located next to the System Managed Credential.

  8. Wait for the dialog confirming: Info: Successfully rotated System managed credential, and click OK.

  9. Click Validate Connection to ensure the test now succeeds.

  10. Click Save to apply the configuration.

Workaround: To immediately bypass the synchronization issue and unblock log collection, individual appliance credentials can be utilized. Edit the failing adapters, uncheck the "System Managed Credential" box, and manually enter the local appliance credentials for the specific domains.

Additional Information

For general configuration instructions, refer to: Configuring VMware Cloud Foundation