VMware Cloud Community
AhmedAtia
Contributor
Contributor

Unable to Open vSphere Web/H5 Clients After Repoint/Reconfigure Embedded VC to External Load-balanced PSC

We face an issue similar to the one mentioned in this post: [500] SSO error: Unable to initialize, java.io.IOException: extra data given to DerValue constructor

We have a single vCenter Server Appliance with an embedded PSC with hostname vcsa.contoso.local .

s1.png

We then deploy two external PSCs; psc1.contoso.local and psc2.contoso.local, joining them to the existing SSO vsphere.local which is hosted in the embedded PSC on vcsa.contoso.local and using the same Site name Default-First-Site.

s2.png

We configured NSX ESG Load Balancer between psc1.contoso.local and psc2.contoso.local, and created a Virtual Server psc.contoso.local as mentioned in KB2147018 (which forwards us to KB2147627, KB2147046, and KB2147384).

s3.png

Then we followed KB2148924 to repoint vcsa.contoso.local with the embedded PSC to psc1.contoso.local (external PSC)

s4.png

s5.png

We then reconfigured vCenter to connect to psc.contoso.local (load-balancer VIP).

s6.png

When we try to open https://vcsa.contoso.local/vsphere-client/ it shows the following error message:

Error

A server error occurred.

[500] SSO error: Unable to initialize, java.io.IOException: extra data given to DerValue constructor

Check the vSphere Web Client server logs for details.

s7.png

If we try to go to https://vcsa.contoso.local/ui/ the following error message appears:

A server error occurred.

[400] An error occurred while sending an authentication request to the vCenter Single Sign-On server - An error occurred when processing the metadata during vCenter Single Sign-On setup - Unable to initialize, java.io.IOException: extra data given to DerValue constructor.

Check the vSphere Client server logs for details.

s8.png

Unfortunately, we didn't create a snapshot of the original vCenter Server with embedded PSC before we started, and we don't currently have a valid backup. We are now unable to log into vSphere Web Client and vSphere Client (HTML5).

Your thoughts are appreciated.

Atia

0 Kudos
2 Replies
parmarr
VMware Employee
VMware Employee

Hello,

Looks like we seem to be having a similar error discussion on [500] SSO error: Unable to initialize, java.io.IOException: extra data given to DerValue constructor...

Please see if this helps

Sincerely, Rahul Parmar VMware Support Moderator
0 Kudos
AhmedAtia
Contributor
Contributor

Hi Parmarr,

Yes, I've already read that post; actually I included a link to it at the beginning of my original post. The other post describes exactly the same issue we are facing. They say that they weren't able to solve it, until they contacted VMware Support, that used an "internal KB" to solve it. Since we are a VMware partner, we are using an NFR license and ran out of our free support codes, therefore unable to open a new ticket with VMware Support, so I was seeking help from the online community.

Any thoughts or ideas are appreciated, really.

Thanks.

Atia

0 Kudos