Creation of a Broker directory fails with domain already exists error
search cancel

Creation of a Broker directory fails with domain already exists error

book

Article ID: 455179

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

When you configure an identity provider and the deployment is interrupted, subsequent attempts to create the identity provider are blocked by hidden remnants.

Saving the configuration settings fails with the following error:

The creation of a Broker directory with name LdapAssociatedDirectory_9158636 failed: Domain with name ExampleTwo.Domain.com already exists

 

Environment

VMware Identity Broker 9.1

Cause

An interrupted initial configuration leaves hidden remnants in the database. The database and directory configuration still have the previous domain bound to the LDAP connection, which prevents the new directory deployment from completing.

This specific issue occurs when there are two domains in the same forest that can be accessed by the same LDAP connection (for example, ExampleOne.domain.com and ExampleTwo.domain.com).

Resolution

To resolve this issue, follow these steps:

  1. Delete the existing directory configuration.

  2. Create the directory configuration again.

  3. Resynchronize the ExampleOne.domain.com directory to remove the stale domain (such as ExampleTwo.domain.com).

  4. Add the domain individually.

  5. Verify with your Active Directory (AD) team that the service account has the necessary permissions to synchronize groups.