VMware Networking Community
Joey2008
Contributor
Contributor
Jump to solution

SSO issue! Can NOT use AD user to log in web-client... administrator@vsphere.local only

I was able to do that when I used Microsoft vCenter, but I just installed VCSA and can't, see below details:

1. VCSA has domain name vcsa.rt.local (AD is rt.local), and VCSA joined AD domain successfully.

Verify: administration->system administration->nodes->vcsa.rt.local (node name)->Active Directory, "Join" grayed out "Leave" is active

2. SSO user and Identity source added successfully

Verify: Administration->SSO->Configuration, "rt.local" added as AD, ->Users and groups, we can see all the AD users from rt.local drop-down rt.local menu.

3. Assign permission successfully

Verify: Global Inventory list->Vcenter server->vcsa.rt.local(server name)->permissions, AD users (RT\nsxadmin) are add to here and gave Administrator Role

Based on document/my MS vcenter experience, I should be able to  nsxadmin@rt.local to log in, but I can't!

Any Idea?

0 Kudos
1 Solution

Accepted Solutions
Sreec
VMware Employee
VMware Employee
Jump to solution

Sorry to hear that.You need to do a basic health check here .I have a strong feeling it is a sync issue .

1. DNS/NTP etc from VC & AD

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered

View solution in original post

0 Kudos
8 Replies
Shawnlo
Contributor
Contributor
Jump to solution

I had read recently of someone having login issues after disabling SMB 1.0 in their domain.  May want to check out this https://virtualizationnation.com/2017/04/17/enabling-vcenter-server-appliance-vcsa-to-use-smb2/  article assuming SMB 1 is disabled in your environment.

0 Kudos
Joey2008
Contributor
Contributor
Jump to solution

Thanks, I tried the article as you mentioned but it didn't work. Thanks anyway.

0 Kudos
Sreec
VMware Employee
VMware Employee
Jump to solution

What is the message you are getting when you are trying to login with AD account ?

Are you able to login via vsphere client using same account ?

Also please try AD/UserName and Password instead of UPN format and let me know the results

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered
0 Kudos
Joey2008
Contributor
Contributor
Jump to solution

Thank you for reply!

I am able to log in now!!!!!!!!!!!!

What is the message you are getting when you are trying to login with AD account ?

That was "invalid credential", today when I tried to get the exact words for you then I found it is working now... I tried 10+ times (2 hours) yesterday, even reset AD password, reboot VCSA,login out many time as administrator@vsphere.local to make sure I don't have CAP. My explanation is too much time for AD to sync up for VC to login? weird enough!

Are you able to login via vsphere client using same account ?

Also please try AD/UserName and Password instead of UPN format and let me know the results

0 Kudos
Joey2008
Contributor
Contributor
Jump to solution

issue still exists!!!!!!!!!!!!!!!!!!!!!!!

I was able to log in as AD users YESTERDAY while I replied.

Right now, "invalid credentials" again, so pissed off...

1. I was able to log in multiple AD users to test privileges Yesterday, all fine. Today issue again.

2. No account change since then

3. Reboot AD, reset password (never expire etc.), won't help

4. AD users can log in domain server/workstation, which means user name/password have NO issue

5. "invalid credentials" response immediately, I suspect it never checks AD to verify...

0 Kudos
Sreec
VMware Employee
VMware Employee
Jump to solution

Sorry to hear that.You need to do a basic health check here .I have a strong feeling it is a sync issue .

1. DNS/NTP etc from VC & AD

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered
0 Kudos
Joey2008
Contributor
Contributor
Jump to solution

Hi Sreec​,

YOU ROCK!

Weeks ago, I got error while trying to join AD, the I fixed time issue.

For this SSO issue, I suspected time issue in the first place and checked the time on AD server and VCSA server, they are the identical.

After you reminded me again, I checked the time again: I found I used manual time in AD server, whenever I checked that auto sync check, it will get wrong time, which means the default NTP server screwed!

So I have to give a correct NTP server manually, there is no simple way so I have to use GPO, see below. After that, I can sync auto correctly, then SSO issue is fixed, amazing!!!!!

Thanks again, NTP is always an issue!!!!

https://www.server-world.info/en/note?os=Windows_Server_2012&p=ntp&f=2

0 Kudos
Sreec
VMware Employee
VMware Employee
Jump to solution

Appreciate that feedback Smiley Happy

Cheers,
Sree | VCIX-5X| VCAP-5X| VExpert 7x|Cisco Certified Specialist
Please KUDO helpful posts and mark the thread as solved if answered
0 Kudos