How to delete invalid and duplicate vSAN and vCenter license entries in vCenter Server
search cancel

How to delete invalid and duplicate vSAN and vCenter license entries in vCenter Server

book

Article ID: 452746

calendar_today

Updated On:

Products

VMware Cloud Foundation

Issue/Introduction

This article describes how to remove invalid and duplicate vSAN and vCenter license asset entries from vCenter Server.

Duplicate vSAN and vCenter licenses may be visible in the vSphere Client by navigating to: vSphere Client > Administration > Licensing > Licenses > Assets > VCENTER SERVER SYSTEMS or VSAN CLUSTERS.

Symptom: Two or more duplicate license asset entries display the same name. However, only one active vCenter or vSAN cluster is actually in use, while the other entries are stale and invalid.

Environment

  • VMware Cloud Foundation 5.x
  • vCenter Server 8.0.x
  • VMware vSAN 8.0.x

 

Cause

This issue typically occurs due to an error during the deployment of a VMware Cloud Foundation (VCF) environment. For example, a user deleted an initial vSAN cluster and created a new one with the same name, then re-assigned the vSAN license to the new cluster. A similar procedure may also cause duplicate vCenter license asset entries.

Resolution

Step 1: Pre-requisites & Backup

  1. Determine whether the vCenter Server is standalone or configured with Enhanced Linked Mode (ELM).

  2. Take Backups:

    • Standalone vCenter Server: Take a virtual machine snapshot (including memory).

    • vCenter Server in ELM: Take an offline (powered-off) snapshot of all vCenter Servers participating in the ELM domain.

  3. ELM Topology Considerations:

    • If the duplicate entries appear on all nodes in ELM, you must break the ELM configuration, perform the cleanup on each vCenter Server sequentially, and then re-join them to ELM.

    • If only a single node is impacted, breaking ELM is not required.

Step 2: Identify Stale Asset Entries

Each asset entry has a unique vmwLicSvcAssetScopeId (which corresponds to the Local Domain Unit / LDU ID of the vCenter Server).

  1. SSH into the vCenter Server Appliance (vCSA).

  2. Gather the LDU IDs of the active vCenter Server nodes via CLI:

    /usr/lib/vmware-vmafd/bin/vmafd-cli get-ldu --server-name localhost

    Note: Comparing these LDU IDs against the asset entries allows you to identify which vCenter or vSAN assets are bound to vCenters that no longer exist.

  3. Run the following LDAP search queries to list all existing vSAN and vCenter asset objects:

    For vSAN Assets:

    /opt/likewise/bin/ldapsearch -LLL -h localhost -p 389 -x -b "dc=vsphere,dc=local" -D "cn=Administrator,cn=Users,dc=vsphere,dc=local" -s sub '(&(vmwLicSvcObjectClass=AssetEntity)(vmwLicSvcAssetProductName=VMware VSAN))' -W

    For vCenter Assets:

    /opt/likewise/bin/ldapsearch -LLL -h localhost -p 389 -x -b "dc=vsphere,dc=local" -D "cn=Administrator,cn=Users,dc=vsphere,dc=local" -s sub '(&(vmwLicSvcObjectClass=AssetEntity)(vmwLicSvcAssetProductName=VMware VirtualCenter Server))' -W

    Note: Ensure that the SSO domain in the base DN (dc=vsphere,dc=local) matches your actual environment. Update it if your domain is different.

Step 3: Analyze LDAP Output

Review the returned LDIF output to differentiate between valid and invalid entries:

  • Managed Object ID (MOID): Embedded within the cn attribute (e.g., cn=AssetEntity_domain-c22-...). Match this against the active cluster MOID.

  • Scope ID: Compare vmwLicSvcAssetScopeId with the LDU ID retrieved in Step 2. Entries containing an LDU ID that no longer exists should be removed.

vSAN Asset Entry Example:

dn: cn=AssetEntity_domain-c#-########-####-####-####-############,cn=LicenseService,cn=services,dc=vsphere,dc=local
cn: AssetEntity_domain-c#-########-####-####-####-############
objectClass: top
objectClass: vmwLicSvcAssetEntity
nTSecurityDescriptor:: AQAHhBQAAAA0AAAAAAAAAFQAAAABBgAAAAAABxUAAADmt0T7shLJoNQ
 6S5rg+bVG9AEAAAEGAAAAAAAHFQAAAOa3RPuyEsmg1DpLmuD5tUYgAgAAAgDAAAUAAAAAExgAMAAA
 AAECAAAAAAAHIAAAAJoCAAAAEygAMwAGAAEGAAAAAAAHFQAAAOa3RPuyEsmg1DpLmuD5tUYDAgAAA
 BMoADMABiABBgAAAAAABxUAAADmt0T7shLJoNQ6S5rg+bVGAAIAAAATKAAzAAYgAQYAAAAAAAcVAA
 AA5rdE+7ISyaDUOkua4Pm1RiACAAAAEygAMwAGIAEGAAAAAAAHFQAAAOa3RPuyEsmg1DpLmuD5tUb
 0AQAA
vmwLicSvcAssetEvalExpiry: YYYY-MM-DDTHH:MM:SS
vmwLicSvcAssetScopeId: ########-####-####-####-############
vmwLicSvcAssetEvalType: SerialKeyEvalType
vmwLicSvcAssetEvalSerialKey: <License key>
vmwLicSvcAssetName: <vSAN Cluster Name>
vmwLicSvcAssetProductVersion: 8.0
vmwLicSvcAssetFeaturesInUseList: allflash
vmwLicSvcAssetProductName: VMware VSAN
vmwLicSvcAssetInstanceId: domain-##
vmwLicSvcAssetCostUnitUsageList: concurrentUser,0,vm,0,cpuPackage,12,cpuPackage:32core,12,cpuCore,288,cpuCore:16core,288,TiB,18
vmwLicSvcAssetId: domain-##-########-####-####-####-############
vmwLicSvcAssetIsInEvaluation: false
vmwLicSvcObjectClass: AssetEntity
vmwLicSvcAssetLicenseId: EvaluationLicenseId

vCenter Asset Entry Example:

dn: cn=AssetEntity_########-####-####-####-############-########-####-####-####-############,cn=LicenseService,cn=services,dc=vsphere,dc=local
cn: AssetEntity_########-####-####-####-############-########-####-####-####-############
objectClass: top
objectClass: vmwLicSvcAssetEntity
nTSecurityDescriptor:: AQAHhBQAAAA0AAAAAAAAAFQAAAABBgAAAAAABxUAAADmt0T7shLJoNQ
 6S5rg+bVG9AEAAAEGAAAAAAAHFQAAAOa3RPuyEsmg1DpLmuD5tUYgAgAAAgDAAAUAAAAAExgAMAAA
 AAECAAAAAAAHIAAAAJoCAAAAEygAMwAGAAEGAAAAAAAHFQAAAOa3RPuyEsmg1DpLmuD5tUYDAgAAA
 BMoADMABiABBgAAAAAABxUAAADmt0T7shLJoNQ6S5rg+bVGAAIAAAATKAAzAAYgAQYAAAAAAAcVAA
 AA5rdE+7ISyaDUOkua4Pm1RiACAAAAEygAMwAGIAEGAAAAAAAHFQAAAOa3RPuyEsmg1DpLmuD5tUb
 0AQAA
vmwLicSvcAssetEvalExpiry: YYYY-MM-DDTHH:MM:SS
vmwLicSvcAssetScopeId: ########-####-####-####-############
vmwLicSvcAssetEvalType: SerialKeyEvalType
vmwLicSvcAssetEvalSerialKey: <License key>
vmwLicSvcAssetName: <vCenter FQDN or Hostname>
vmwLicSvcAssetProductVersion: 8.0
vmwLicSvcAssetVersion: 8.0.4.1
vmwLicSvcAssetProductName: VMware VirtualCenter Server
vmwLicSvcAssetInstanceId: ########-####-####-####-############
vmwLicSvcAssetCostUnitUsageList: server,1
vmwLicSvcAssetId: c57e3580-05bf-439d-8682-24b27d92e3e2-eb102e42-5e58-4883-8f4c-c4dde9eb2634
vmwLicSvcAssetIsInEvaluation: false
vmwLicSvcObjectClass: AssetEntity
vmwLicSvcAssetLicenseId: 2c110962-29fb-4873-bb52-3c815223e95f

 

Step 4: Delete Stale Asset Entries

Once you have identified the Distinguished Name (dn) of the stale entry, execute the ldapmodify command to delete it.

Delete a stale vSAN asset entry:

/opt/likewise/bin/ldapmodify -h localhost -D "cn=administrator,cn=users,dc=vsphere,dc=local" -w '<real password>' << EOF
dn: cn=AssetEntity_domain-c#-########-####-####-####-############,cn=LicenseService,cn=services,dc=vsphere,dc=local
changetype: delete
EOF

Delete a stale vCenter asset entry:

/opt/likewise/bin/ldapmodify -h localhost -D "cn=administrator,cn=users,dc=vsphere,dc=local" -w '<real password>' << EOF
dn: cn=AssetEntity_########-####-####-####-############-########-####-####-####-############,cn=LicenseService,cn=services,dc=vsphere,dc=local
changetype: delete
EOF
 
In this step, enter the information corresponding to the highlighted section in the example into the 'dn' line. 
 

Step 5: Restart the License Service

After deleting the stale LDAP objects, restart the VMware License Service to refresh the vSphere Client inventory:

service-control --restart cis-license