/var/log/vmware/vmdird/vmdird-syslog.log show vmdir changing to an unrecoverable state following a reboot or service restart.[YYYY-MM-DDTHH:MM:SS] err vmdird t@140008367298304: _VmDirConsumePartner: Did not succesfully perform any updates after full pull. Moving vmdir to an unrecoverable state
[YYYY-MM-DDTHH:MM:SS] info vmdird t@140008367298304: VmDir State (5)
[YYYY-MM-DDTHH:MM:SS] err vmdird t@140008367298304: vdirReplicationThrFun: Replication has failed with unrecoverable error.
[YYYY-MM-DDTHH:MM:SS] err vmdird t@140008241473280: _VmDirSearchPreCondition: Server in not in normal mode, not allowing outward replication.
[YYYY-MM-DDTHH:MM:SS] err vmdird t@140008241473280: VmDirSendLdapResult: Request (Search), Error (LDAP_UNWILLING_TO_PERFORM(53)), Message (Server in not in normal mode, not allowing outward replication.), (0) socket (10.10.10.10)
LegacyAliasMappings cn.[YYYY-MM-DDTHH:MM:SS] err vmdird t@140008367298304: InternalDeleteEntry: VdirExecutePostDeleteCommitPlugins - code(9117)
[YYYY-MM-DDTHH:MM:SS] warning vmdird t@140008367298304: ReplDeleteEntry/VmDirInternalDeleteEntry: 66 (Operation not allowed on non-leaf). DN: cn=LegacyAliasMappings,cn=vsphere.local,cn=Tenants,cn=IdentityManager,cn=Services,DC=vsphere,DC=local, first attribute: cn, it's meta data: '659195:2:abdefg-3891-435f-7afc-6b9636240bb3:20230429035650.714:426961'. NOT resolving this possible replication CONFLICT. For this object, system may not converge. Partner USN 0
LegacyAliasMapping. This will cause vmdir to go into the same failure mode. The action plan will be the same in these cases. # /usr/lib/vmware-vmafd/bin/dir-cli domain-functional-level getThis issue is resolved in vCenter Server 8.0 Update 2. To download, go to Download Broadcom products and software.
/usr/lib/vmware-vmafd/bin/dir-cli domain-functional-level set --level 4 --login [email protected] --domain-name vsphere.local
Note: Update vsphere.local to match current SSO domain name. service-control --restart vmdird
This issue is being checked by Diagnostics for VMware Cloud Foundation.
The check is as follows:
ReplDeleteEntry/VmDirInternalDeleteEntry:" AND "Operation not allowed on non-leaf"The workaround is also effective in scenarios where VDT reports the following error:
[FAIL] VMdir DFL Check
VMDIR Domain Functional Level is incorrect!
Note:
While running step 1 of the Workaround you may receive an error:dir-cli failed, error= Invalid Domain Functional Level
Verify that level is valid for domain. 9129
If you encounter the above error while following the workaround, contact Broadcom Support and note this Article ID (318221) in the problem description. For more information, see Creating and managing Broadcom support cases.