VMware Cloud Community
RobMerritt
Contributor
Contributor

Problems with VCSA sso login

I have home lab and trying to log into

https://vcsa67.homenet.local/websso/SAML2/SSO/homenet.local?SAMLRequest=

using root@homenet.local

I can authenticate as root and using the cli password but I get

Unable to login because you do not have permission on any vCenter Server systems connected to this client

any idea how to troubleshoot this?

Tags (1)
0 Kudos
4 Replies
scott28tt
VMware Employee
VMware Employee

Moderator: Thread moved to the vCenter Server area.


-------------------------------------------------------------------------------------------------------------------------------------------------------------

Although I am a VMware employee I contribute to VMware Communities voluntarily (ie. not in any official capacity)
VMware Training & Certification blog
0 Kudos
NicolasAlauzet

Did you try to access with administrator@homenet.local ? This is master admin for your vcenter server (the password is the one you configured during deployment)

Also, open a new window just in case, connecto to https://vcsa67.homenet.local/  then authenticate

-------------------------------------------------------------------
Triple VCIX (CMA-NV-DCV) | vExpert | MCSE | CCNA
0 Kudos
nachogonzalez
Commander
Commander

if you are able to access using administrator@vsphere.local please check if there is an idenitity source for homenet.local

https://geek-university.com/vmware-esxi/sso-identity-sources/#:~:text=An%20identity%20source%20is%20...

0 Kudos
IRIX201110141
Champion
Champion

A account like "root@homenet.local" doesnt looks like a standard setup.

The VCSA comes with 2 identity sources by default:

1. "@localos". There is a "root@localos" but this account have NO PERMISSION to the WebClient by default. Yes you can add root@localos to the WebClient. You cannot create users within localos through the GUI

2. "@vsphere.local" or how you named the SSO Domain during installation.  Here you have the administrator@vsphere.local which have admin rights within WebClient by default. Yes you can create more user accounts under vpshere.local and assign them to WebClient

If you would like to login VAMI aka https://vcsa:5480 than you need the "root" only.

Regards,
Joerg

0 Kudos