Cannot complete the configuration of the vSphere HA agent on the hostSetting desired image spec for cluster failedALARM Unable to find vSphere HA master agentCannot find vSphere HA master agentvCenter Server is unable to find a master vSphere HA agent in cluster <cluster name> in <datacenter name> DatacentervSphere HA agent for this host has an error: The vSphere HA agent is not reachable from vCenter Server2025-01-23T11:09:34.746-08:00] [ERROR] http-nio-5090-exec-2022 70244956 102516 200171 c.v.vsphere.client.provisioning.ovf.impl.OvfDeployServiceImpl Unable to query OVF. com.vmware.vapi.std.errors.InternalServerError: InternalServerError (com.vmware.vapi.std.errors.internal_server_error) => { messages = [LocalizableMessage (com.vmware.vapi.std.localizable_message) => { id = vapi.bindings.method.impl.unexpected, defaultMessage = Provider method implementation threw unexpected exception: com.vmware.vapi.std.errors.Unauthorized, args = [com.vmware.vapi.std.errors.Unauthorized], params = <null>, localized = <null>}, LocalizableMessage (com.vmware.vapi.std.localizable_message) => { id = com.vmware.vdcs.vsphere-auth-lib.permission.denied, defaultMessage = Permission to perform this operation was denied., args = [], params = <null>, localized = <null>}], data = <null>, errorType = INTERNAL_SERVER_ERROR2025-01-12T02:29:02.581-08:00 [tomcat-exec-85 [] INFO AuthorizationService.AuditLog opId=] Action performed by principal(name=VSPHERE.LOCAL\Administrator,isGroup=false):Added access control [ Principal=Name= VSPHERE.LOCAL\vpxd-<string of ####>,isGroup=false,roles=[-5],propogating=true ] to document urn:acl:global:permissionsThe vCenter Server's solution users play vital roles in performing regular vCenter functions. Below is a list of vCenter Server's solution users:
When these solution users do not have the correct administrator permission, vCenter's tasks and workflows are degraded.
root@vcenter [ ~ ]# /usr/lib/vmware-vpx/scripts/authz-doctor/authz-doctor.py permission_checkauthz-doctor version: 9.0.0.0-14454563Argument --user is not provided. Results will be limited.Permission Check results:1. Permissions list:+-------------------------------------------------------------------------+-------+------------+-----------------------------------+-----------+----------+| Principal | Group | Role Id | Role Name | Propagate | Entity |+-------------------------------------------------------------------------+-------+------------+-----------------------------------+-----------+----------+| VSPHERE.LOCAL\vpxd-568da01a-2c55-44a2-8d33-669b25ada0b3 | False | -5 | None | True | Global || VSPHERE.LOCAL\vpxd-extension-568da01a-2c55-44a2-8d33-669b25ada0b3 | False | -1 | Admin | True | Global || VSPHERE.LOCAL\vpxd-svc-acct-568da01a-2c55-44a2-8d33-669b25ada0b3 | False | -1 | Admin | True | Global || VSPHERE.LOCAL\vpxd-svcs-user-568da01a-2c55-44a2-8d33-669b25ada0b3 | False | -1 | Admin | True | Global || VSPHERE.LOCAL\vsphere-ui-568da01a-2c55-44a2-8d33-669b25ada0b3 | False | 1003 | vSphere Client Solution User | True | Global || VSPHERE.LOCAL\vsphere-webclient-568da01a-2c55-44a2-8d33-669b25ada0b3 | False | 1003 | vSphere Client Solution User | True | Global |+-------------------------------------------------------------------------+-------+------------+-----------------------------------+-----------+----------+Note: It is not required for the vCenter Server services to be restarted for this to go into effect.