VMware Cloud Community
Gamecock
Contributor
Contributor

Single Sign On Error

Has anyone else recently experienced log in issues with the HTML-5 VCenter Manager portal?

I was able to log in utilizing our admin network domain account with no issues up until two weeks ago.

Now I'm being forced to browse into each VM host separately instead of the vsphere web client.

 

Any Ideas on what may have changed? Browser or windows security updates?

 

What we get is invalid certificate or a provided credentials are not valid when i know they are.

Then loops back to the home page.

Reply
0 Kudos
11 Replies
berndweyand
Expert
Expert

what vSphere-version do you have ?

can you login with administrator@vsphere.local?

check your certificates (root, machine, solutions and sts)

 

Reply
0 Kudos
Gamecock
Contributor
Contributor

I'm on version ESXi 6.5 from what I can tell from our records.

I have tried the administrator@vsphere.local? and still get the same error. I've also tried the root account with no luck.

There seems to be issues with the certificate but I would not know where to retrieve the correct one or replace what I have.

I can tell you that we are on.

VMware vCenter Server Appliance
Version:
6.5.0.30000
Reply
0 Kudos
berndweyand
Expert
Expert

but you can ssh into the appliance with root?

then please check the certs manually https://kb.vmware.com/s/article/2111411

can you tell us the exact certificate error message?

Gamecock
Contributor
Contributor

Ok I will see if I can get this information for you. Sorry for the late response.

 

Reply
0 Kudos
Gamecock
Contributor
Contributor

Hey I will be honest with you.

I am having a very hard time following the knowledge based article you shared with me.

I can open up and sign into putty but all of the commands are not found.

I'm sure its something I am not typing correctly.  :disappointed_face:

 

Reply
0 Kudos
Gamecock
Contributor
Contributor

Gamecock_0-1627054419461.png

Gamecock_1-1627054492152.png

 

 

Reply
0 Kudos
berndweyand
Expert
Expert

after putty into the vcsa did you open the shell with "shell" - then all commands must be available.

but your screenshots shows that you have no cert problem - its seem to be invalid credentials

 

Reply
0 Kudos
Gamecock
Contributor
Contributor

Hi Let me try that. 

I just signed into it and started working from the prompt that rested after the host name.

 

Thanks

Reply
0 Kudos
Ajay1988
VMware Employee
VMware Employee

Can u share a screenshot of the error about certificates ? 
Also run the below command and see if any cert is expired?

for i in $(/usr/lib/vmware-vmafd/bin/vecs-cli store list); do echo STORE $i; sudo /usr/lib/vmware-vmafd/bin/vecs-cli entry list --store $i --text | egrep "Alias|Not After"; done

Also check if STS is sexpired >> https://kb.vmware.com/s/article/79248

If you think your queries have been answered
Mark this response as "Correct" or "Helpful".

Regards,
AJ
Reply
0 Kudos
Gamecock
Contributor
Contributor

Hi Ajay1988,

 

Sorry for the late response. Yes the issue is still there.

Please see the print screens and let me know if you need more information.

 

Gamecock_0-1629378241233.png

 

Gamecock_1-1629378320185.png

I'm also getting these errors when I try to putty into our vcenter server. I know this is the correct ip address, but somethings is wrong.

 

I also get a not found error when I try to enter the command provided under the host command prompt.

Gamecock_0-1629379083490.png

 

 

Reply
0 Kudos