VMware

This Question is Answered

1 "correct" answer available (10 pts) 1 "helpful" answer available (6 pts)
1 2 Previous Next 20 Replies Last post: Aug 26, 2009 5:44 AM by bulletprooffo…  

Domain Admin account lock out attempts coming from Virtual Center??? posted: Dec 18, 2008 6:01 AM

Click to view SandyB's profile Enthusiast 114 posts since
Nov 1, 2005

We changed our Domain Admin password a few days ago and now on our new Netcrunch monitoring platform we are being spammed by messages saying the domain Administrator account is being locked out from our Virtual Center server....

there are no scheduled tasks or services that run using this account and i cant find anywhere within the Virtual Center application that would hold these credentials.

does anyone have any ideas? :_|

Click to view NTurnbull's profile Expert 429 posts since
Feb 11, 2008
Hi, If you go into VC and look at the current sessions, do you have any pre-password change sessions for dom admin? Or do you have you got any RDP sessions open logged in as dom admin?

Thanks,
Neil

Click to view Rajeev S's profile Hot Shot 193 posts since
Oct 27, 2006
Hi,

You can try using ALTools(ALockout.dll) from microsoft. This would list the process which is causing the lockout.

http://www.microsoft.com/downloads/details.aspx?FamilyId=7AF2E69C-91F3-4E63-8629-B999ADDE0B9E&displaylang=en

Hope this helps.

Click to view jayolsen's profile Master 547 posts since
Jul 31, 2006
Maybe a server trying to start as the domain admin. If you open your services snap-in and sort by Log On As column look for domain\administrator account. If so the password probably needs updated within that server.
Click to view khughes's profile Virtuoso 1,478 posts since
Jan 8, 2008

I was going to say the same thing. If you install the virtualcenter with this domain account there are some services that run under it. If you changed your password recently this could cause your account lockout.


  • Kyle
Click to view vmroyale's profile Virtuoso 1,712 posts since
Jun 15, 2007
See if either of these commands turns up anything:

tasklist /FI "USERNAME eq domain\DomainAdmin"

at

Good Luck!
Click to view vpert's profile Enthusiast 43 posts since
Mar 2, 2007

We do have exactly the same issue.

We did a complete new install of every VMware component on this server - no luck. Then we reinstalled the hole server from scratch. We did NOT use the account in question for any installation step. We did NOT even logon with this account to the server - no luck.

When we had the ALockout.dll running the virtualcenter server did not start anymore - so no findings from there. We get every 5 minutes the following events in the Security log on the server as soon the virtualcenter service starts:
Event ID 680 - Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_1_0, with the Logon account of the user in question
right after that a Event ID 529 - Logon failure: Unknown user name or bad password with the User name Logon Process Advapi

Well and after 5 attempts in our case the account gets locked out.

If anyone has a idea how we could trace this further or even solve the issue - help would be really appreciated!

Click to view NTurnbull's profile Expert 429 posts since
Feb 11, 2008
Hi, do you have update manager installed? Did you enter your account details in the Update manager proxy configuration?

EDIT: Oh and If you do have update manager installed and using NT Authentication, step back through your ODBC DSN setup as it stores an encrypted version of the users password in the registry

Thanks,
Neil

Click to view vpert's profile Enthusiast 43 posts since
Mar 2, 2007
Hi Neil,

thanks for your ideas. Update Manager is installed - but no proxy settings, no ODBC entries with this account.

We did a complete new install of the system - everything from scratch! There must be some account information either on the ESX Servers or the running VM's.....

We did further testing - just had VMware Components installed (VirtualCenter, UpdateManager uso) without any ESX Host connected the user account is used for login as soon as the virtualcenter service is started. So we guess the user account information must come from ??? Active Directory maybe? any ideas?

rgds

Tom

Nachricht geändert durch vpert
OK - did some further analysis: The account get locked out because it's used by the vpxd.exe process (virtualcenter Service). The Event shows a logon type 2 which is "Interactive - logon at keyboard and screen of system" ????? The system we are talking about is a virtual machine?? ...it is getting scary ;-( ....no Console or RDP Sessions open to this system. So I changed the service account from "Local System" to a user account - no luck. The domain account is still used every 5 minutes.
Does anyone have a idea how we can findout why the VirtualCenter Service tries to logon with this domain user account?

Nachricht geändert durch vpert
Issue solved: I finally did a network trace and found out that every 5 minutes there was a communication from the VirtualCenter to a certain system. ...and guess what this system was avirtual appliance with the vkernel CBA running. Well stupid - forgot all about - this appliance is connecting to the virtualcenter to collect statistic information and therefor needed a user account.
Changed the users password in the CBA and that was it!
Thx for everbodies help and hope this will give you a hint Sandy.

Click to view OM4EVER's profile Enthusiast 61 posts since
Oct 17, 2006
You know I'm actually having the same problem. Account keeps getting locked out on the domain controllers, I have traced the service to the VPXD service on VC however, I'm not sure what machine keeps trying to do the authentication. From the VC machine, I've done a netstat -anbv and it shows all the machines communicating with process. I still don't see anything that's out of the ordinary, only my ESX servers. how else can I find out? Need help, please
Click to view abstract's profile Lurker 2 posts since
Jul 29, 2006

Hi, I have just changed the password on my personal admin account and after investigation I have discovered that Virtual Center and specifically the Virtual Center service is locking it out. I change the password frequently however I have not seen this problem in the past.

I stopped the Virtual Center service for a couple of hours and there were no bad password attempts so I'm 100% sure this is the culprit.

Did anyone get to the bottom of this?

Cheers.

Click to view abstract's profile Lurker 2 posts since
Jul 29, 2006

I have exactly the same problem after changing the password on my personal admin account.

Did anyone get to the bottom of this?

Cheers.

Click to view OM4EVER's profile Enthusiast 61 posts since
Oct 17, 2006
When I had this problem it turned out to be a our monitoring utility from Vizioncore that for some unknown reason was attempting to authenticate using my Domain ID. We had to re-install the authentication module and the problem went away

VMware Developer

SDKs, APIs, Videos, Learn and much more in the Developer community.

Learn More

Developer Sample Code

Increase your developer productivity with VMware API sample code.

Learn More

VMworld Sessions & Labs

Online access to the latest VMworld Sessions & Labs and online services.

Learn more

Purchase PSO Credits Online

Purchase credits to redeem training and consulting services online.

Buy Now

Community Hardware Software

View reported configurations or report your own.

Learn More

VMware vSphere

Come witness the next giant leap in virtualization.

Register Today

Communities