VMware Cloud Community
PartenaOZV
Contributor
Contributor

Failed to communicate with the vCenter Single Sign On server

Dear

This morning we couldn't connect to our machine anymore so we physically restarted the server.

After reboot we could no longer log on using our Domain accounts. (Web client and Vsphere Client)

Setup was done by previous IT crew and local password never documented.

However i've found a way to reset the default password using How to Reset SSO (administrator@vsphere.local) Password - YouTube .

This seems to work as I get confirmation from my new password but even with this password I still can't log in.

pastedImage_1.png

Could you please tell me what else I can try or check as we can no longer access our Vsphere environment.

0 Kudos
9 Replies
ThompsG
Virtuoso
Virtuoso

Hi PartenaOZV and welcome to the community!

Could you confirm whether you have an external or internal SSO? Also is this a Windows vCenter or vCSA deployment?

Kind regards.

0 Kudos
PartenaOZV
Contributor
Contributor

Hello ThompsG

This is a Windows Vsphere.

How can I verify which SSO is used ?

0 Kudos
MikeStoica
Expert
Expert

What version are you running?

0 Kudos
PartenaOZV
Contributor
Contributor

Vsphere 5.5

0 Kudos
MikeStoica
Expert
Expert

Restart the SSO service from Windows Services and try again

0 Kudos
PartenaOZV
Contributor
Contributor

I don't seem to have a Single Sign on Service

pastedImage_0.png

However problem came after having to reboot the server physically and after the physical reboot I did a clean reboot.

0 Kudos
MikeStoica
Expert
Expert

It's the VMware Identity Management Service.

0 Kudos
PartenaOZV
Contributor
Contributor

Already restarted in previous attempts, however now we've reinstalled our SSO completely from the install cd.

Now we get a different error when trying to connect:

pastedImage_0.png

When trying to create a new cert. via openssl we get the following error :

pastedImage_1.png

0 Kudos
ThompsG
Virtuoso
Virtuoso

Hi PartenaOZV,

You have gone a little off the beaten path now Smiley Wink

Firsly download the vCenter Certificate Automation Tool v5.5 as located here: https://kb.vmware.com/s/article/2057340

From here you should be able to get vCenter to trust the new certificates on the SSO deployment. One of the options is to plan your steps and there should be an option for SSO cert replacement/trust. This will tell you what steps to run.

This may not work however as vCenter actually registers with SSO on install so you may need to recreate the registration as well given your SSO is now newly created. I would test in a LAB but one option would be to ensure you have a good backup of the database and then reinstall vCenter over the top.

Kind regards.

0 Kudos