vCenter

 View Only
  • 1.  VCenter Server locking out AD user

    Posted Mar 07, 2012 06:05 PM

    I've got a very strange problem with VCenter Server... it appears that it's storing my domain username and OLD password somewhere (likely the account I used to initially install it).  Since then I've gotten a dedicated AD username to use (nonexpiring pwd), and reinstalled VCenter (keeping the database) so all services are using the new AD account.  The problem is that as soon as I changed my AD Password, vpxd started locking out my account within a minute or two.  I've insured that vpxd and vctomcat are using the new domain user.  I've insured that the database login credentials/odbc connection also use the new user... but still it has my old user SOMEWHERE.  I suspect it must be in the database (or dog forbid in an ini file) because it's not in the registry.

    Anyone have any ideas?  I've definitely gotten some gray hair out of this one.



  • 2.  RE: VCenter Server locking out AD user
    Best Answer

    Posted Mar 07, 2012 08:48 PM

    Have you by chance registered Update Manager, Converter or any other vCenter plug-in service with vCenter using your AD account?

    Do you have an idle or disconnected Terminal services session on the vCenter server that you logged in before you changed your password?



  • 3.  RE: VCenter Server locking out AD user

    Posted Mar 07, 2012 08:55 PM

    That was it... almost... it was VMWare Data Recovery VM's that were causing the problem.  I ended up blowing more than half the day before I tracked it down (with the help of the logs).  Thanks for the tip!



  • 4.  RE: VCenter Server locking out AD user

    Posted Jun 06, 2012 01:50 AM

    lloks like i have the same problem. can you point where in the logs did you find out about this??



  • 5.  RE: VCenter Server locking out AD user

    Posted Jun 06, 2012 12:45 PM

    Well it's a bit of a memory test... but I seem to recall seeing some entries related to VDR daily backups failing.  I don't think it was obvious from the error text that the problem was authentication or it would have been easier to figure out.