500 - {"errorCode":"IDENTITY_INTERNAL_SERVER_ERROR","arguments":[],"message":"Identity Internal Server Error","referenceToken":"####"}.SDDC 4.x
SDDC 5.x
This issue occurs because the SDDC Manager SSL certificate is either expired or does not include the IP address in the Subject Alternative Name (SAN) field.
When you attempt to log in via the IP address, the identity services encounter a certificate mismatch or an invalid trust path, resulting in the following exception in the logs:
/var/log/vmware/vcf/commonsvcs/vcf-commonsvcs.logCaused by: com.vmware.vim.vmomi.client.exception.SslException: javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
To restore access to the SDDC Manager UI, you must use one of the following methods:
Access the SDDC Manager UI using the Fully Qualified Domain Name (FQDN) instead of the IP address. This aligns the request with the existing certificate parameters and circumvents the SAN mismatch.
If you require direct access to the UI via an IP address, you must regenerate the SDDC certificate to include the IP as a SAN:
/opt/vmware/sddc-support/sos --certificate-health