VMware Cloud Community
KM_MPL1
Contributor
Contributor

Random Domain User authentication failure

Im having a randomly occurring event with the domain admin, which is part of Administrators group on vCentre. Attempting to login to the web console with " domain.local\Administrator" or "domain\Administrator" will intermittently fail. Even using the authenticator plugin, it will fail on authentication sometimes. It varies which one will work "domain.local\" or "domain\", also both may fail but the authenticator application will allow login (which shows the "domain\") being used. Adding to that, log out, and try with the method that failed before, and it will work.

This is not computer specific either, trying on a vm running inside the vm environment, a laptop, another desktop. Only thing common is this is using the web console in chrome. DNS does not seem to be an issue on the network. Looking in the events for the Datacentre in vm web console, i see no authentication errors.

Another issue which I'm sure has to do with this in some way, Veeam backups run over night and will fail halfway through with authentication failure trying to snapshot VM's. In an attempt to try and get successful backups, I broke the backups down; one at 2200HRS and another later at 0400HRS. The 2200HRS backup failed halfway through with authentication issues, the 0400HRS backup proceeded successfully, having only one VM to backup.

I dont know what would be causing these authentication issues, and whats further stranger, is how "domain.local\" wont work but when specifying "domain\" will work, or vice versa. This issue has been a recent one, only starting within the last 2 months.

At no time has the domain admin account in use here ever been locked out, password does not expire.

vCentre 6.7 Build 11727113

ESXi 6.7 Build 10302608

0 Kudos
3 Replies
Vijay2027
Expert
Expert

Did you find anything interesting in websso.log and ssoAdminserver.log from /var/log/vmware/sso dir.

Search with the domain user name in the above log files.

0 Kudos
KM_MPL1
Contributor
Contributor

I cant find anything with with the Domain Admin account in. Updated to 6.7 U3b and the issue still occurs. Shut down backup server incase it was a locked account etc. and still persists. Also, occurs with another user account in the same AD group that is added to the Administrators group, so its definitely not an authentication lockout issue.

0 Kudos
rshenoy
Enthusiast
Enthusiast

By any chance was this password change recently?

Regards

Ritesh

0 Kudos