Authentication Failure Between NSX and VMware Identity Manager
search cancel

Authentication Failure Between NSX and VMware Identity Manager

book

Article ID: 451807

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

  • Users may be unable to authenticate to NSX using VMware Identity Manager (vIDM).
  • The environment may show the user in the user list, but users cannot be added to groups.
  • This article provides the steps to resolve authentication errors during login attempts, specifically error code 71008.

Environment

  • VMware Cloud Foundation (VCF)
  • NSX-T
  • VMware Identity Manager (vIDM)

Cause

The Single Sign-On (SSO) target URL within the VMware Identity Manager application catalog is configured with an incorrect URI for the NSX integration.

Resolution

Update the Single Sign-On URL to use the correct URL and URI combination.

  1. Navigate to the VMware Identity Manager application catalog.
  2. Locate the NSX integration configuration.
  3. Update the Single Sign-On (SSO) target URL to: https://####/vidm-oauth2-login
    1. Note: Replace #### with the exact NSX-FQDN or IP address.
  4. Verify that the hostname or IP address in the SSO URL is an exact match to the value provided when initially registering the NSX Manager with VMware Identity Manager.
  5. Save the configuration changes.
  6. Attempt the authentication again to validate the connection.

Additional Information

NSX single sign-on integration within the VMware Identity Manager application catalog requires the specific /vidm-oauth2-login URI path to properly route OAuth2 requests. The exact match mandate ensures that identical hostnames or IP addresses are used between the SSO URL and the registration configuration.

To speak with a customer representative or a Support Engineer, see Contact Support. Scroll to the bottom of the page and click on your respective region.