When attempting to add permissions to a VMware vCenter Server inventory object via the vSphere Client (GUI), the OK button remains unresponsive after entering Active Directory user/group details, preventing the registration of new permissions.
ssoAdminServer.log): [com.vmware.identity.idm.server.ServerUtils] cannot establish ldap connection with URI: [ldap://<dc_fqdn>] because [com.vmware.identity.interop.idm.IdmNativeException] with reason [Native platform error [code: 41737][LW_ERROR_KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN][Client not found in Kerberos database]]Product: VMware vCenter Server
Configuration: The Identity Source Type is Active Directory (Integrated Windows Authentication).
The issue is caused by a communication or authentication failure between the vCenter Server and the Active Directory Domain Controller. Specifically, the Kerberos identity of the user account may be missing or invalid in the AD database (LW_ERROR_KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN), preventing the Single Sign-On (SSO) service from binding to the directory to validate the selected user/group.
If the user account utilized during the configuration of the Identity Source is invalid, the issue can be resolved via one of the following two approaches:
These should immediately allow you to add permissions again without requiring a full re-join of the domain.
Integrated Windows Authentication (IWA) has been deprecated and is no longer supported in vCenter 9.0.