After performing a vCenter Server upgrade, attempting to reconfigure the Protection and Recovery Appliance Management may fail with a drConfig.fault.NotAuthorized error. This issue occurs when the vCenter administrator account loses its required membership in the SSO Administrators group.
A general system error occurred: N7Vmacore9ExceptionE Fault cause: drConfig.fault.NotAuthorizedva-config.log report a SOAP fault during connection validation.Log Evidence: The issue is confirmed by the following error sequence found in the VLR Appliance:
YYYY-MM-DDTHH:MM:SS.MS+HH:MM INFO va-config 3170 [VaConfig@4413 sub="vmomi.soapStub[12]" opID="#######################################################"] SOAP request returned HTTP failure; <SSL(<io_obj t:N7Vmacore6System19TCPSocketObjectAsioE, h:36, <TCP '##.##.#.## : 38592'>, <TCP '##.##.#.## : 443'>>), /sso-adminserver/sdk/[FQDN]>, method: hasAdministratorRole; code: 500(Internal Server Error); fault: (sso.fault.NoPermission) {
--> faultCause = (vmodl.MethodFault) null,
--> faultMessage = <unset>
--> msg = "Received SOAP response fault from [<SSL(<io_obj t:N7Vmacore6System19TCPSocketObjectAsioE, h:36, <TCP '##.##.#.## : 38592'>, <TCP '##.##.#.## : 443'>>), /sso-adminserver/sdk/[FQDN]>]: hasAdministratorRole
--> "
--> }
YYYY-MM-DDTHH:MM:SS.MS+HH:MM ERROR va-config 3170 [VaConfig@4413 sub="Default" opID="#######################################################"] Validate SSO admin role failed:
--> (drConfig.fault.NotAuthorized) {
--> faultCause = (vmodl.MethodFault) null,
--> faultMessage = <unset>
--> msg = ""
--> }
The [email protected] account (or the service account used for registration) has lost its membership in the Administrators group within the vCenter SSO domain following a vCenter upgrade.
vsphere.local domain.Administrators group and ensure [email protected] is listed as a member.[email protected] back to the Administrators group.