SDDC Manager displays stale, missing, or outdated passwords for VNA appliances for up to 3 hours after deployment or redeployment in VCF 9.1
search cancel

SDDC Manager displays stale, missing, or outdated passwords for VNA appliances for up to 3 hours after deployment or redeployment in VCF 9.1

book

Article ID: 451272

calendar_today

Updated On:

Products

VMware NSX VMware Cloud Foundation VMware SDDC Manager / VCF Installer

Issue/Introduction

After deploying or redeploying VNA appliances in a VMware Cloud Foundation 9.1 environment, the SDDC Manager credential store does not immediately reflect the current, accurate passwords for those appliances. Specifically:

  • Passwords for newly deployed VNA appliances are unavailable or fail to retrieve from SDDC Manager.
  • Passwords displayed in SDDC Manager are stale and do not match the credentials currently set on the appliance.
  • After a cluster is removed and redeployed with the same names/FQDNs, SDDC Manager returns the credentials of the previously removed cluster.
  • Passwords changed manually on the appliance are not reflected in SDDC Manager after an Inventory Sync.
  • No passwords are displayed at all for the appliances following a reboot.
  • Manually triggered Inventory Sync operations do not resolve any of the above.
  • Credentials populate correctly on their own after approximately three hours, with no administrator action.

This article explains the expected discovery and synchronization workflow for VNA appliance credentials, clarifies which operations are and are not affected by the delay, and describes how to reduce the synchronization interval if required.

Symptoms

One or more of the following may be observed following the deployment, redeployment, or out-of-band password change of VNA appliances:

  • Attempts to retrieve VNA appliance passwords from SDDC Manager fail or return no data within the first hours after deployment.
  • Passwords are manually changed directly on the VNA appliance, an Inventory Sync is run, and SDDC Manager continues to display the original pre-change passwords.
  • After a VNA cluster is removed and a new cluster is deployed reusing the same names and FQDNs, the auto-generated passwords retrieved from SDDC Manager match the credentials of the previously removed cluster rather than the newly deployed appliances.
  • After rebooting the VNA appliances, SDDC Manager displays no passwords at all for the appliances.
  • Repeated manual Inventory Sync operations produce no change in the displayed credentials, even after waiting 2 to 2.5 hours.
  • Credentials eventually populate correctly with no further administrator action, typically at an interval of approximately three hours from the last automated background sync.

Environment

VMware NSX 9.1
VMware Cloud Foundation 9.1
VMware SDDC 9.1

Cause

This behavior is expected and is a function of how SDDC Manager discovers VNA appliances. It is not a defect in credential synchronization, and it is not generic to all newly deployed appliance types, the delay is specific to VNA.

The contributing factors are:

1. VNA appliances are discovered only by the automated background sync. Because the VNA appliances are deployed through the vCenter workflow rather than through SDDC Manager, SDDC Manager has no immediate awareness of them. It discovers these appliances only during its automated background inventory synchronization job, which runs every 3 hours by default.

2. Manual Inventory Sync does not apply to VNA appliances. Manually triggered sync operations do not cover VNA discovery and will not force an update. This is why repeated manual resyncs in the field produce no change and why the credential store only refreshes on the scheduled interval. The eventual ~3 hour update reflects the next scheduled run of the background job, not the manual syncs.

3. Inventory sync does not reconcile out-of-band password changes. None of the inventory sync operations, automated or manual, automatically update stored credentials when a password has been changed out-of-band directly on the VNA appliance. This explains why SDDC Manager continued to display pre-change passwords after the appliance-side change and subsequent resync. A separate credential remediation operation is required in SDDC Manager to reconcile out-of-band password changes, and that operation is only possible after the initial automated inventory sync has completed and the node is present in inventory.

4. Redeployment with reused names/FQDNs. Where a cluster is removed and redeployed with the same names and FQDNs before the background sync has run, SDDC Manager's inventory still holds the prior cluster's records. Credentials retrieved during this window will therefore correspond to the removed cluster. The records are reconciled on the next scheduled background sync.

Resolution

This is expected product behavior in VCF 9.1 VNA node deployments. No corrective action is required to obtain accurate credentials the credential store populates correctly once the automated background inventory sync completes.

Recommended workflow

  1. After deploying or redeploying VNA appliances, allow up to 3 hours for the automated background inventory sync to discover the appliances and populate the credential store. Manual Inventory Sync operations during this window will have no effect and are not required.

  2. Do not treat the absence of credentials as a blocker to system access. The sync delay only prevents SDDC Manager from managing or rotating the initial VNA passwords immediately after deployment. It does not block access to the appliance. Users can reset password using [Action] menu in the VNA panel in NSX Manager GUI and then log into VNA with the password. However, eventually SDDC Manager will reset password when it discovers VNA and password will change.
  3. If a password was changed out-of-band on the appliance, wait for the initial automated inventory sync to complete, confirm the node is present in SDDC Manager inventory, and then perform a credential remediation operation in SDDC Manager to reconcile the changed password. Inventory sync alone will not pick up the change.

  4. When redeploying a cluster with the same names/FQDNs, expect credentials retrieved before the next background sync to reflect the prior cluster. Allow the scheduled sync to complete before validating credentials.

Additional Information

Is the delay expected for future password rotations?

No. The 3-hour delay is a one-time condition specific to the period immediately following deployment, while the appliance is not yet present in SDDC Manager inventory.

Once the VNA node appears in the SDDC Manager inventory, future password rotations occur immediately, on demand, at the administrator's discretion. Scheduled or compliance-driven password rotations performed after initial discovery are not subject to any multi-hour delay.

What remains subject to the sync interval?

Other out-of-band topology changes continue to be picked up only on the scheduled background sync interval. This includes, but is not limited to:

  • Adding nodes outside of SDDC Manager
  • Deleting nodes outside of SDDC Manager
  • Modifying appliance FQDNs

Changes of this type should be expected to reflect in SDDC Manager within one background sync cycle (3 hours by default).

For password management after SDDC Manager sync, refer to
https://techdocs.broadcom.com/us/en/vmware-cis/vcf/vcf-9-0-and-later/9-1/design/vmware-cloud-foundation-concepts/nsx-virtual-network-appliance-cluster-models.html