/var/log/vmware/trustmanagement/trustmanagement-svcs.log and /var/log/vmware/vsphere-ui/logs/vsphere_client_virgo.log:trustmanagement-svcs.log:
<YYYY-MM-DD>T<HH:MM:SS> WARNING trustmanagement-svcs ## [vc@#### threadName="pool-#-thread-#" logger="com.vmware.iam.txaz.client.VidbClient"] Caught exception while fetching the client ########-####-####-####-############ detailsjava.lang.RuntimeException: Failed to get the access token. at com.vmware.iam.txaz.client.VidbClient.getClientAccessToken(VidbClient.java:###) at com.vmware.iam.txaz.client.VidbClient.getOAuthClient(VidbClient.java:###) at com.vmware.iam.txaz.secretrotation.ClientSecretRotator.lambda$initSecretRotationTask$0(ClientSecretRotator.java:##)
vsphere_client_virgo.log:
<YYYY-MM-DD>T<HH:MM:SS> ERROR vsphere-ui ##### [vc@#### threadName="http-nio-127.0.0.1-####-exec-###" logger="com.vmware.skyscraper.oauth2.common.Oauth2Helper" ######## ###### ###### ] Exception while exchanging token with csp with for code <CODE> and state ########-####-####-####-############. Csp responded with status 401 UNAUTHORIZED and body {"error":"invalid_client","error_description":"oauth2.authorization.credentials.invalid"}
VCF 9.1.0
Note: Either the following procedure or "Method 2: Manually rotate the VC's OAuth2 client secret and then patch the IDP configuration with the new secret." may be used to resolve this issue.
Refresh the OAuth2 client registration and credentials by unjoining and rejoining the SSO domain for the vCenter appliance.