Quantcast
Channel: VMware Communities : Popular Discussions - vCenter™ Server
Viewing all 18256 articles
Browse latest View live

vCenter 5.1 SSO and failure to successfully authenticate users

$
0
0

I have experienced this problem with the 5.1 upgrade including the latest 5.1.0b. In fact the latest patch makes it impossible to add users explicitly via the vSphere client whereas previously I could do this.

 

The problem description is as follows:

  • Users do not authenticate via the web client or via vSphere client
  • Users receive the error "Cannot complete login due to an incorrect user name or password" on the vSphere client
  • Users receive the error "The authentication server returned an unexpected error: ns0:RequestFailed: Internal Error while creating SAML 2.0 Token. The error may be caused by a malfunctioning identity source.

 

Things I have tried:

  • I have followed this article but the solution re: RPC server not available does not apply as this does not appear in the logs @ http://kb.vmware.com/kb/2034798
  • Added new domain users
  • Explicitly added users in the vSphere client giving them full administrative privileges and propogating to all child objects
  • Domain groups which the users are part of (IT Operations) are added under SSO administrators group (SSO Users and Groups --> Groups --> __Administrators__ have the principals 'ITOperations' and 'Domain Admins' - they are both Active Directory groups)

 

Observations:

  • Putting the user in the 'Domain Admins' group allows the user to successfully log-in to both vSphere and web clients - obviously this is not a practical solution to the problem but unsure as to why it works - members of the IT Operations group can successfully log-in to the vCenter server so also unsure as to what permissions would be required for this to work.
  • Granting users explicit access via the vSphere client used to work in previous version of 5.1.0 - with 5.1.0b the users get the "Cannot complete login" error

 

Our set-up:

  • vCenter sits on Server 2008 R2 Enterprise
  • Active Directory runs in our environment and handles all log-ins - SSO should be set-up to intergrate itself with AD but not sure why it's not working
  • 1 ESXi 5.0 host

 

imsTrace log:

2013-01-03 13:48:51,781, [castle-exec-1], (LocalisAccessHelper.java:567), trace.com.rsa.ims.localis.LocalisAccessHelper, DEBUG, vCenter.Company.local,,,,Invoking GetAllLocalOSDomains() Local OS call
2013-01-03 13:48:51,842, [castle-exec-1], (LocalisAccessHelper.java:575), trace.com.rsa.ims.localis.LocalisAccessHelper, DEBUG, vCenter.Company.local,,,,GetAllLocalOSDomains Local OS call status 0
2013-01-03 13:48:51,855, [castle-exec-1], (LocalisAccessHelper.java:523), trace.com.rsa.ims.localis.LocalisAccessHelper, DEBUG, vCenter.Company.local,,,,Invoking GetUserGroupsByName(COMPANY\vspheretest) Local OS call
2013-01-03 13:48:51,958, [castle-exec-1], (LocalisAccessHelper.java:531), trace.com.rsa.ims.localis.LocalisAccessHelper, DEBUG, vCenter.Company.local,,,,GetUserGroupsByName Local OS call status 6
2013-01-03 13:48:51,964, [castle-exec-1], (GroupAccessLocalIS.java:313), trace.com.rsa.ims.admin.dal.localis.PrincipalAccessLocalIS, DEBUG, vCenter.Company.local,,,,Lookup failure: [GroupInfo.c:254] NetUserGetLocalGroups failed: Access is denied.

 

2013-01-03 13:48:51,969, [castle-exec-1], (SecurityTokenServiceImpl.java:117), trace.com.rsa.riat.sts.impl.SecurityTokenServiceImpl, ERROR, vCenter.Company.local,,,,Error while trying to generate RequestSecurityTokenResponse
com.rsa.common.UnexpectedDataStoreException: Unexpected Local OS exception
    Caused by: com.rsa.ims.localis.LocalisAccessError: Local O/S Identity Source Error: LOCALIS_STATUS_INTERNAL, extended error: 5 : [GroupInfo.c:254] NetUserGetLocalGroups failed: Access is denied.

 

imsRuntimeAudit log:

2013-01-03 13:48:51,580, <longstring1>,<longstring2>,,192.168.0.110,AUTHN_LOGIN_EVENT,13002,SUCCESS,AUTHN_METHOD_SUCCESS,<longstring3>,<longstring4>,<longstring5>,<longstring6>,vspheretest,vspheretest,SYSTEM,,,,,,000000000000000000001000f0022001,LDAP_Password,,,,,,,,,,,,,

 

vpxd log:

2013-01-03T13:48:50.565Z [00620 info '[SSO]' opID=C001001B-00000004-3b] [UserDirectorySso] Authenticate(vspheretest, "not shown")
2013-01-03T13:48:52.049Z [00620 error '[SSO]' opID=C001001B-00000004-3b] [UserDirectorySso] AcquireToken SsoException: Unexpected SOAP fault: ns0:RequestFailed; request failed.
2013-01-03T13:48:52.049Z [00620 error 'authvpxdUser' opID=C001001B-00000004-3b] Failed to authenticate user <vspheretest>
2013-01-03T13:48:56.051Z [00620 info 'commonvpxLro' opID=C001001B-00000004-3b] [VpxLRO] -- FINISH task-internal-574 --  -- vim.SessionManager.login --
2013-01-03T13:48:56.051Z [00620 info 'Default' opID=C001001B-00000004-3b] [VpxLRO] -- ERROR task-internal-574 --  -- vim.SessionManager.login: vim.fault.InvalidLogin:
--> Result:
--> (vim.fault.InvalidLogin) {
-->    dynamicType = <unset>,
-->    faultCause = (vmodl.MethodFault) null,
-->    msg = "",
--> }
--> Args:
-->


vCenter - Greyed out "take snapshot"

$
0
0

I am currently running ESXi 4.1 Update 2 hosts and vCenter Server 4.1 Update 2.  I am also running VMware Data Recovery 1.2.1.1616.

 

Several of my VMs have stopped receiving successful backups from vDR and I am unable to capture a snapshot of several of my VMs.  vDR gives the following error:  "Failed to create snapshot for XXXservernameXXX, error -3941"

The "Take Snapshot" option is also greyed out when I attempt to take a snapshot on these VMs manually as well using the vSphere Client connected to vCenter Server.

 

However, I am able to select "Take Snapshot" when connected via the vsphere Client directly to the host.

 

My backups have been working properly until a couple days ago.

 

The VMs that aren't working all happen to be created off of the same template and are all Server 2008 R2.

All of my hard disks are standard SCSI VHDs.  There are no orphaned snapshots on the datastore that I see and there are no snapshots in the snapshot manager.

 

I am curious if anyone else has come across this issue.  Thanks in advance!

Error when loading VMWare vSphere Client

$
0
0

Hey guys, I'm a newbie to the VMWare world and have just experienced my first problem. 

 

My system was installed by a 3rd party vendor that, due to uncontrolable circumstatnces, is not accessible at this time.  So, I'm attempting to see if anyone might have a resolution for me.

 

I'm using ESX 4.  When I open the vSphere Client application and enter my login credentials, I receive the following slew of errors:

 

     The specified module could not be found. (Exception from HRESULT: 0x8007007E)

 

     This application has failed to start because MSVCR71.dll was not found. Re-installing the application may fix this problem.

 

     VMware Remote Console unrecoverable error: (player)

     SSLLoadSharedLibrary: Failed to load library libeay32.dll:126

 

The last error writes a dump file.

 

This application has always worked flawlessly.  The problem started while I was on a business trip last week.  I'm suspecting that some type of update (Microsoft, Java, etc.) is probably what is causing this issue.

 

I tried re-registering the dll files but it didn't make a difference.  I would love to re-install the application as suggested, but I'm currently unable to locate that download on VMware's site.

 

I'm just curious if anyone has any suggestions or possibly the location of the downloads?

 

Thanks in advance,

Steve

vCenter Server Appliance 5.1 - Wizard/Config fails

$
0
0

This is my inital step into the Vmware world and it isn't going well.

 

Downloaded the latest vCenter Server appliance  5.1.0.5100 and created a new VM in VMware Workstation 8.0.4.

 

Started the VM and let it work it's way through the install.

 

browse (Firefox 15.0.1) to https://10.1.5.7:5480 and I log in using root & the default password.  Get the EULA & accept.

 

The wizard starts.  Select the config with default settings then select Start.

 

During SSO I get:

Failed to execute '/usr/sbin/vpxd_servicecfg sso write embedded embedded     CENSORED  CENSORED':
VC_CFG_RESULT=702(Error: An unexpected error ocurred during the installation of the appliance SSO service. Please collect a support bundle and file a service request.)

 

Starting vCenter Server I get:

Failed to execute '/usr/sbin/vpxd_servicecfg sso write embedded embedded     CENSORED  CENSORED':
VC_CFG_RESULT=702(Error: An unexpected error ocurred during the installation of the appliance SSO service. Please collect a support bundle and file a service request.)
Failed to execute '/usr/sbin/vpxd_servicecfg service start':
VC_CFG_RESULT=101(Error: vCenter Server failed to start.)

 

 

I thought that a fully packaged VM with a wizard would at least give me a nearly functioning setup.

 

I've tried setting the hostname/static IP.  No difference

Configure database was set to embedded by the wizard.  Since this will be a small installation (2 ESXi hosts, <30 clients) that should be sufficient.

Trying to change the SSO deployment type always fails with "Error: VPXD must be stopped to perform this operation."

Configure Authentication/Configure Services don't go anywhere.

 

Trying a custom configuration gave the same results.

 

Anyone have an idea as to what I'm doing wrong?

The VMware vCenter Inventory Service service terminated with service-specific error Incorrect function..

$
0
0

Tried connecting into the web interface and it states it cannot connect to the inventory server.  I see the service is stopped and when I try to start it, it fails.  Error message in event log: The VMware vCenter Inventory Service service terminated with service-specific error Incorrect function..

 

I have rebooted the server and had the same issue.  I have a backup of the SQL/server but I have never ran the backup.bat as referred to in here: VMware KB: vCenter Inventory Service fails to start and cannot back up the Inventory Service database

 

I cannot seem to find a great article on what will be impacted by resetting the service fresh?

vCenter server suddenly stops working

$
0
0

Hi all,

 

Every once in a while (about 2 times a week) vCenter service stops with the following error in event viewer:

 

Faulting application name: vpxd.exe, version: 5.0.0.29542, time stamp: 0x4f3e030b
Faulting module name: KERNELBASE.dll, version: 6.1.7601.17651, time stamp: 0x4e21213c
Exception code: 0xe06d7363
Fault offset: 0x000000000000cacd
Faulting process id: 0x2508
Faulting application start time: 0x01cd5f03f44df961
Faulting application path: C:\Program Files\VMware\Infrastructure\VirtualCenter Server\vpxd.exe
Faulting module path: C:\Windows\system32\KERNELBASE.dll
Report Id: 1795e64c-cc17-11e1-902b-0050568400f6

 

My DB is Oracle and everything looks good on DB (at least that's what my DBA says).

 

When it happens, I just start the service and everything works well again.

The vCenter machine has 8GB RAM and 4vCPUs and is a Windows 2008 R2.

 

Thank for any information,

 

Razvan Stoica

vCenter Appliance 6.0 Email Notification Issue

$
0
0

Hi all,

 

I have deployed vCenter appliance 6.0 but it is not able to send out email alerts. I came across this KB article: VMware KB: Emails sent from VMware vCenter Server Appliance are rejected but this is not working for me. Am not sure where the issue is. Though when I run one of the commands in the KB, I get a warning. The command is

 

     /sbin/conf.d/SuSEconfig.sendmail -m4 > /sendmail.mc

 

The warning is:

 

    Warning! MD5DIR is not set: you probably called this script outside SuSEconfig...!

     Using MD5DIR="/var/adm/SuSEconfig/md5"...

 

I am not much of a linux person so please excuse my ignorance if this can be safely ignored.

 

The email is received at the SMTP server but the sender email address is <garbage.garbage@<vCenter appliance FQDN>. Now this is dropped by the mail servers as it does not conform to the correct format. If I use PowerCLI, I am able to connect to the vCenter and send the email with this syntax:

 

     send-mailmessage -smtp <smtp server> -to <receiver email address> -Subject "Subject" -from <sender email address>

 

Any ideas what is going on. I have a ticket open but GSS is not being very useful.

vSphere Web Client - Do not have access to a vCenter Server 5.1 system

$
0
0

Using vSphere Web Client 5.1
Trying to access vcenter 5.1 server

 

Logged in as admin@system-domain

No vcenter server listed.

Suggested troubleshooting steps:

Verify that the vCenter Server system was registered with the vSphere Web Client's Lookup Service.
Question: How do I verify this?

 

Logged in using Windows Session Authentication.
(User is a memeber of Administrators with full access to vCenter Server)

Message: Client is not authenticated to VMware Inventory Service.
No vcenter server listed

Question: How do I troubleshoot this?

 

Thank you.


Web Client throws Error #2032 when accessed through any sort of reverse proxy / SSL VPN

$
0
0

I've been trying to publish the Web Client through our SSL VPN which has a nice workspace to publish web links.

 

Unfortunately, something in the vSphere web client breaks very badly if you do not connect directly to the application - it loads the background image but instead of displaying the login dialog it simply bombs out with an "Error #2032" message.

 

Anyone found a fix for this?

Host Profiles playing up in vSphere 5

$
0
0

Hi all,

 

Ive recently upgraded about 200 hosts to ESXi 5 from ESX 4.1 and 2 vcenters 5 also.

Ive noticed a problem with host profiles when it comes to storage, and wanted to see if anyone else has come across it.

 

Basically its only happening on the HP BL620 G7 but the older HP BL680 G5's are unaffected.

 

When creating a profile from an existing host, That host it is created off obviously is compliant, but all the rest come back with saying that the local disk naa that was in the host it was created from is missing.. this only happens on the G7's might have something to do with a newer controller in the hosts?

 

Ok thats ok i edited the profile and removed that naa from the check but then the hosts are coming back with

 

Host state doesnt match specification: device (naa of local storage for that host) needs to be reset

Host state doesnt match specification: device (naa of local storage for that host) Path Selection Policy needs to be set to default for claiming SATP

 

Looking at the profile the default for VMW_SATP_LOCAL is fixed which is what the disk is set at.

 

Any one seen this? I have removed something from the check but seams to make things worse, I dont mind at the moment because I know the hosts are compliant I would like a big green tick instead of a big red cross

 

Cheers

Update Manager patch repository

$
0
0

Does anyone know of a way to remove/delete old patches from the patch repository in Update Manager ?

 

I'm running all ESXi 4.1 and I want to remove all the old ESX 4.0 patches, and other os patches that we do not run to clean up the repository.

 

Any ideas ? maybe a utility or CLI that might do the trick ?

 

Thanks in advance.

Unable to login to vSphere Web Client - [500] SSO error: Cannot connect to the VMware Component Manager

$
0
0

Hi,

 

I have been testing out the latest vSphere, and have ran in to an issue with the vCenter Server Appliance.

 

I was able to access it via its web address as well as by the vSphere Client but after I rebooted the host that it was running on I can no longer access it.

This is for both the web address and client.

When I go to the address i get the usual certificate warning but after that I get:

 

A server error occurred.

[500] SSO error: Cannot connect to the VMware Component Manager

 

The vCenter Server Appliance is a virtual instance on the host.

 

I am able to connect directly to the host and the VM is running, as I can open the console session to it.

 

All this occurred after I rebooted the host to complete the install of the Mega RAID CLI and LSI Provider .VIB's

 

Any ideas?

 

Thanks,

Marcus

Unable to start the vCenter / Management Web Services

$
0
0

Hi All,

 

I recently moved our vCenter installation to another server "vCenterServer" from the original server "Win12-ban", I have left the database on "Win12-ban" and created a DSN on "vCenterServer" which tests successfully when connecting into the database from the "vCenterServer" database. When I originally set this all up it worked a dream, I was originally using my own domain account to start the service (rather than the local system account), but now none of these accounts will start the service. I really want to be using the local account as I want to be able to see performance stats within vcenter.

 

The error message I get when trying to start the service is:

 

screenshot1.JPG

Followed by this in the event viewer:

 

Log Name: Application
Source:   VMware VirtualCenter Server
Date:     06/01/2014 09:29:28
Event ID: 1000

Task Category: None

Level:    Error
Keywords: Classic
User:     N/A
Computer: vCenterServer.

 

The description for Event ID 1000 from source VMware VirtualCenter Server cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.

 

If the event originated on another computer, the display information had to be saved with the event.

 

The following information was included with the event:

 

Error getting configuration info from the database

 

I have tested the DSN from the machine with vCenter installed and it tests successfully, which suggests there is a connection from the vCenter Server to the database, has anyone encountered similar issues?

vCenter 5.1 SSO and failure to successfully authenticate users

$
0
0

I have experienced this problem with the 5.1 upgrade including the latest 5.1.0b. In fact the latest patch makes it impossible to add users explicitly via the vSphere client whereas previously I could do this.

 

The problem description is as follows:

  • Users do not authenticate via the web client or via vSphere client
  • Users receive the error "Cannot complete login due to an incorrect user name or password" on the vSphere client
  • Users receive the error "The authentication server returned an unexpected error: ns0:RequestFailed: Internal Error while creating SAML 2.0 Token. The error may be caused by a malfunctioning identity source.

 

Things I have tried:

  • I have followed this article but the solution re: RPC server not available does not apply as this does not appear in the logs @ http://kb.vmware.com/kb/2034798
  • Added new domain users
  • Explicitly added users in the vSphere client giving them full administrative privileges and propogating to all child objects
  • Domain groups which the users are part of (IT Operations) are added under SSO administrators group (SSO Users and Groups --> Groups --> __Administrators__ have the principals 'ITOperations' and 'Domain Admins' - they are both Active Directory groups)

 

Observations:

  • Putting the user in the 'Domain Admins' group allows the user to successfully log-in to both vSphere and web clients - obviously this is not a practical solution to the problem but unsure as to why it works - members of the IT Operations group can successfully log-in to the vCenter server so also unsure as to what permissions would be required for this to work.
  • Granting users explicit access via the vSphere client used to work in previous version of 5.1.0 - with 5.1.0b the users get the "Cannot complete login" error

 

Our set-up:

  • vCenter sits on Server 2008 R2 Enterprise
  • Active Directory runs in our environment and handles all log-ins - SSO should be set-up to intergrate itself with AD but not sure why it's not working
  • 1 ESXi 5.0 host

 

imsTrace log:

2013-01-03 13:48:51,781, [castle-exec-1], (LocalisAccessHelper.java:567), trace.com.rsa.ims.localis.LocalisAccessHelper, DEBUG, vCenter.Company.local,,,,Invoking GetAllLocalOSDomains() Local OS call
2013-01-03 13:48:51,842, [castle-exec-1], (LocalisAccessHelper.java:575), trace.com.rsa.ims.localis.LocalisAccessHelper, DEBUG, vCenter.Company.local,,,,GetAllLocalOSDomains Local OS call status 0
2013-01-03 13:48:51,855, [castle-exec-1], (LocalisAccessHelper.java:523), trace.com.rsa.ims.localis.LocalisAccessHelper, DEBUG, vCenter.Company.local,,,,Invoking GetUserGroupsByName(COMPANY\vspheretest) Local OS call
2013-01-03 13:48:51,958, [castle-exec-1], (LocalisAccessHelper.java:531), trace.com.rsa.ims.localis.LocalisAccessHelper, DEBUG, vCenter.Company.local,,,,GetUserGroupsByName Local OS call status 6
2013-01-03 13:48:51,964, [castle-exec-1], (GroupAccessLocalIS.java:313), trace.com.rsa.ims.admin.dal.localis.PrincipalAccessLocalIS, DEBUG, vCenter.Company.local,,,,Lookup failure: [GroupInfo.c:254] NetUserGetLocalGroups failed: Access is denied.

 

2013-01-03 13:48:51,969, [castle-exec-1], (SecurityTokenServiceImpl.java:117), trace.com.rsa.riat.sts.impl.SecurityTokenServiceImpl, ERROR, vCenter.Company.local,,,,Error while trying to generate RequestSecurityTokenResponse
com.rsa.common.UnexpectedDataStoreException: Unexpected Local OS exception
    Caused by: com.rsa.ims.localis.LocalisAccessError: Local O/S Identity Source Error: LOCALIS_STATUS_INTERNAL, extended error: 5 : [GroupInfo.c:254] NetUserGetLocalGroups failed: Access is denied.

 

imsRuntimeAudit log:

2013-01-03 13:48:51,580, <longstring1>,<longstring2>,,192.168.0.110,AUTHN_LOGIN_EVENT,13002,SUCCESS,AUTHN_METHOD_SUCCESS,<longstring3>,<longstring4>,<longstring5>,<longstring6>,vspheretest,vspheretest,SYSTEM,,,,,,000000000000000000001000f0022001,LDAP_Password,,,,,,,,,,,,,

 

vpxd log:

2013-01-03T13:48:50.565Z [00620 info '[SSO]' opID=C001001B-00000004-3b] [UserDirectorySso] Authenticate(vspheretest, "not shown")
2013-01-03T13:48:52.049Z [00620 error '[SSO]' opID=C001001B-00000004-3b] [UserDirectorySso] AcquireToken SsoException: Unexpected SOAP fault: ns0:RequestFailed; request failed.
2013-01-03T13:48:52.049Z [00620 error 'authvpxdUser' opID=C001001B-00000004-3b] Failed to authenticate user <vspheretest>
2013-01-03T13:48:56.051Z [00620 info 'commonvpxLro' opID=C001001B-00000004-3b] [VpxLRO] -- FINISH task-internal-574 --  -- vim.SessionManager.login --
2013-01-03T13:48:56.051Z [00620 info 'Default' opID=C001001B-00000004-3b] [VpxLRO] -- ERROR task-internal-574 --  -- vim.SessionManager.login: vim.fault.InvalidLogin:
--> Result:
--> (vim.fault.InvalidLogin) {
-->    dynamicType = <unset>,
-->    faultCause = (vmodl.MethodFault) null,
-->    msg = "",
--> }
--> Args:
-->

VMware VirtualCenter Server Service not starting

$
0
0

I've been fighting with this issue for a while now and haven't been able to find a solution - even with checking the posts on this forum.

 

I am running VMware vCenter Server 5.1.0.32743 on a Windows 2008R2 physical server (not on a domain). Whenever I make a hardware change (ie, adding a SCSI card) the VirtualCenter Server service (and also the VirtualCenter Management Webservices service) refuses to start.

 

When I remove the SCSI card the issue still persists and the only way for me to resolve so far is to restore the server from backup - obviously not ideal and I need to connect tape drives to this server.

 

servicenotstarting1.png

 

I get the standard event 1000 in event viewer also.

 

I have tried changing the service startup types so that SSO service comes up first (as suggested in one of the KB articles) but this has no effect.

 

The back end of the vpxd-xx.log file shows this:

 

2012-11-22T12:35:51.780Z [00564 info 'vpxdvpxdMoOptionManager'] [OptionManagerMo] Invoking callbacks for key log.level, pre commit
2012-11-22T12:35:51.780Z [00564 info 'vpxdvpxdMoOptionManager'] [OptionManagerMo] Invoking callbacks for key log.level, pre commit
2012-11-22T12:35:51.780Z [00564 info 'vpxdvpxdMoOptionManager'] [OptionManagerMo] No change to log.level
2012-11-22T12:35:51.780Z [00564 info 'vpxdvpxdMain'] [VpxdMain] Setting OpenSSL verify locations CAFile=C:\ProgramData\VMware\SSL\ca_certificates.crt CAPath=C:\ProgramData\VMware\SSL
2012-11-22T12:35:51.780Z [00564 info 'Default'] Creating SSL Contexts
2012-11-22T12:35:51.858Z [00564 info 'utilvpxdDbParallelLoader'] Num rows: 6, num CPUs: 4, threads: 1, step: 6
2012-11-22T12:35:51.921Z [00564 info 'Default'] [VpxdResourcePoolHostMirror::SetRoot] root moref vim.ResourcePool:resgroup-8 in mirror for host vim.HostSystem:host-10
2012-11-22T12:35:51.921Z [00564 info 'Default'] [VpxdResourcePoolHostMirror::SetRoot] root moref vim.ResourcePool:resgroup-8 in mirror for host vim.HostSystem:host-13
2012-11-22T12:35:51.921Z [00564 info 'Default'] [VpxdResourcePoolHostMirror::SetRoot] root moref vim.ResourcePool:resgroup-53 in mirror for host vim.HostSystem:host-54
2012-11-22T12:35:53.028Z [00564 warning 'VpxProfiler'] Vpxd::ServerApp::Init [VpxdInvtHost::Init2(gDB)] took 1108 ms
2012-11-22T12:35:53.059Z [00564 info 'vmdasVm'] [VmMo::SetDesiredDasProtectState] desired protection state for VM vm-241 'unprotected' -> 'protected'
2012-11-22T12:35:53.059Z [00564 info 'vmdasVm'] [VmMo::UpdateActualDasProtectStateLocked] actual protection state for VM vm-241 'n/a' -> 'protected'
2012-11-22T12:35:53.059Z [00564 info 'vmdasVm'] [VmMo::SetDesiredDasProtectState] desired protection state for VM vm-61 'unprotected' -> 'protected'
2012-11-22T12:35:53.059Z [00564 info 'vmdasVm'] [VmMo::UpdateActualDasProtectStateLocked] actual protection state for VM vm-61 'n/a' -> 'protected'
2012-11-22T12:35:53.059Z [00564 info 'vmdasVm'] [VmMo::SetDesiredDasProtectState] desired protection state for VM vm-59 'unprotected' -> 'protected'
2012-11-22T12:35:53.059Z [00564 info 'vmdasVm'] [VmMo::UpdateActualDasProtectStateLocked] actual protection state for VM vm-59 'n/a' -> 'protected'
2012-11-22T12:35:53.059Z [00564 info 'vmdasVm'] [VmMo::SetDesiredDasProtectState] desired protection state for VM vm-60 'unprotected' -> 'protected'
2012-11-22T12:35:53.059Z [00564 info 'vmdasVm'] [VmMo::UpdateActualDasProtectStateLocked] actual protection state for VM vm-60 'n/a' -> 'protected'
2012-11-22T12:35:53.059Z [00564 info 'vmdasVm'] [VmMo::SetDesiredDasProtectState] desired protection state for VM vm-57 'unprotected' -> 'protected'
2012-11-22T12:35:53.059Z [00564 info 'vmdasVm'] [VmMo::UpdateActualDasProtectStateLocked] actual protection state for VM vm-57 'n/a' -> 'protected'
2012-11-22T12:35:53.106Z [00564 info 'dbdbPortgroup'] [VpxdInvtDVPortGroup::PreLoadDvpgConfig] loaded [0] dvpg config objects
2012-11-22T12:35:53.106Z [00564 info 'authvpxdMoSessionManager'] [SSO][SessionManagerMo::Init] Admin URI set to: https://10.105.110.110:7444/sso-adminserver/sdk
2012-11-22T12:35:53.106Z [00564 info 'authvpxdMoSessionManager'] [SSO][SessionManagerMo::Init] Downloading STS Root certificates ...
2012-11-22T12:35:53.122Z [00496 info 'Default'] Thread attached
2012-11-22T12:35:53.153Z [00564 error 'vpxdvpxdMain'] [Vpxd::ServerApp::Init] Init failed: Unexpected exception
--> Backtrace:
--> backtrace[00] rip 000000018018977a
--> backtrace[01] rip 0000000180100c98
--> backtrace[02] rip 0000000180101fae
--> backtrace[03] rip 000000018008aeab
--> backtrace[04] rip 0000000000514971
--> backtrace[05] rip 00000000004b1298
--> backtrace[06] rip 00000000004b16c9
--> backtrace[07] rip 0000000000420fae
--> backtrace[08] rip 000000014040bfb8
--> backtrace[09] rip 000000013f300078
--> backtrace[10] rip 000000013f30016a
--> backtrace[11] rip 000000013f300279
--> backtrace[12] rip 000000013f300609
--> backtrace[13] rip 000000013f642903
--> backtrace[14] rip 000000013fdee4b9
--> backtrace[15] rip 000000013fde835c
--> backtrace[16] rip 0000000140008a3b
--> backtrace[17] rip 000007fefecda82d
--> backtrace[18] rip 000000007764652d
--> backtrace[19] rip 00000000779dc521
-->
2012-11-22T12:35:53.153Z [00564 warning 'VpxProfiler'] ServerApp::Init [TotalTime] took 4353 ms
2012-11-22T12:35:53.153Z [00564 error 'Default'] Failed to intialize VMware VirtualCenter. Shutting down...
2012-11-22T12:35:53.153Z [00564 info 'vpxdvpxdSupportManager'] Wrote uptime information
2012-11-22T12:36:00.813Z [03108 warning 'VpxProfiler' opID=SWI-eac14804] VpxUtil_InvokeWithOpId [TotalTime] took 12012 ms
2012-11-22T12:36:12.825Z [03108 warning 'VpxProfiler' opID=SWI-63f9e37] VpxUtil_InvokeWithOpId [TotalTime] took 12012 ms
2012-11-22T12:36:24.837Z [03108 warning 'VpxProfiler' opID=SWI-b155aed1] VpxUtil_InvokeWithOpId [TotalTime] took 12012 ms
2012-11-22T12:36:36.849Z [03108 warning 'VpxProfiler' opID=SWI-7a9c1975] VpxUtil_InvokeWithOpId [TotalTime] took 12012 ms
2012-11-22T12:36:48.861Z [03108 warning 'VpxProfiler' opID=SWI-a2d6fb25] VpxUtil_InvokeWithOpId [TotalTime] took 12012 ms
2012-11-22T12:36:49.126Z [00564 info 'Default'] Forcing shutdown of VMware VirtualCenter now

 

 

Interestingly (and this is where I cannot find anything online relating to this) discover-is from C:\Program Files\VMware\Infrastructure\SSOServer\utils\logs shows:

 

 

2012-11-21 16:15:07,110 - DDNBGF5J,,,,Executing action: 'discover-is'

2012-11-21 16:15:07,111 - DDNBGF5J,,,,Discovering identity sources

2012-11-21 16:15:08,022 - DDNBGF5J,,,,ERROR: Could not access HTTP invoker remote service at [https://10.105.110.110:7444/ims/CommandServer]; nested exception is org.apache.commons.httpclient.HttpException: Did not receive successful HTTP response: status code = 404, status message = [Not Found]

org.springframework.remoting.RemoteAccessException: Could not access HTTP invoker remote service at [https://10.105.110.110:7444/ims/CommandServer]; nested exception is org.apache.commons.httpclient.HttpException: Did not receive successful HTTP response: status code = 404, status message = [Not Found]

     at org.springframework.remoting.httpinvoker.HttpInvokerClientInterceptor.convertHttpInvokerAccessException(HttpInvokerClientInterceptor.java:212)

     at org.springframework.remoting.httpinvoker.HttpInvokerClientInterceptor.invoke(HttpInvokerClientInterceptor.java:145)

     at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:172)

     at org.springframework.aop.framework.JdkDynamicAopProxy.invoke(JdkDynamicAopProxy.java:202)

     at $Proxy0.executeCommand(Unknown Source)

     at com.rsa.command.CacheableHttpInvokerTarget.executeCommand(HttpInvokerCommandTarget.java:261)

     at com.rsa.command.DelegatingCommandTarget.executeCommand(DelegatingCommandTarget.java:66)

     at com.rsa.command.TargetableCommand.execute(TargetableCommand.java:270)

     at com.rsa.authn.LoginCommand.execute(LoginCommand.java:612)

     at com.rsa.authn.AuthenticatedTargetImpl.login(AuthenticatedTargetImpl.java:161)

     at com.rsa.command.ConnectionFactory$ConnectionImpl.connect(ConnectionFactory.java:754)

     at com.rsa.command.ConnectionFactory.connect(ConnectionFactory.java:542)

     at com.rsa.riat.tools.internal.Utils.login(Utils.java:1050)

     at com.rsa.riat.tools.is.DiscoverIdentitySources.execute(DiscoverIdentitySources.java:81)

     at com.rsa.riat.tools.ConfigureRIATCmd.execute(ConfigureRIATCmd.java:192)

     at com.rsa.riat.tools.ConfigureRIATCmd.main(ConfigureRIATCmd.java:517)

Caused by: org.apache.commons.httpclient.HttpException: Did not receive successful HTTP response: status code = 404, status message = [Not Found]

     at org.springframework.remoting.httpinvoker.CommonsHttpInvokerRequestExecutor.validateResponse(CommonsHttpInvokerRequestExecutor.java:214)

     at org.springframework.remoting.httpinvoker.CommonsHttpInvokerRequestExecutor.doExecuteRequest(CommonsHttpInvokerRequestExecutor.java:131)

     at org.springframework.remoting.httpinvoker.AbstractHttpInvokerRequestExecutor.executeRequest(AbstractHttpInvokerRequestExecutor.java:136)

     at org.springframework.remoting.httpinvoker.HttpInvokerClientInterceptor.executeRequest(HttpInvokerClientInterceptor.java:192)

     at org.springframework.remoting.httpinvoker.HttpInvokerClientInterceptor.executeRequest(HttpInvokerClientInterceptor.java:174)

     at org.springframework.remoting.httpinvoker.HttpInvokerClientInterceptor.invoke(HttpInvokerClientInterceptor.java:142)

     ... 14 more

2012-11-21 17:20:55,979 - DDNBGF5J,,,,Executing action: 'discover-is'

2012-11-21 17:20:55,979 - DDNBGF5J,,,,Discovering identity sources

2012-11-21 17:20:56,884 - DDNBGF5J,,,,ERROR: Could not access HTTP invoker remote service at [https://10.105.110.110:7444/ims/CommandServer]; nested exception is org.apache.commons.httpclient.HttpException: Did not receive successful HTTP response: status code = 404, status message = [Not Found]

org.springframework.remoting.RemoteAccessException: Could not access HTTP invoker remote service at [https://10.105.110.110:7444/ims/CommandServer]; nested exception is org.apache.commons.httpclient.HttpException: Did not receive successful HTTP response: status code = 404, status message = [Not Found]

     at org.springframework.remoting.httpinvoker.HttpInvokerClientInterceptor.convertHttpInvokerAccessException(HttpInvokerClientInterceptor.java:212)

     at org.springframework.remoting.httpinvoker.HttpInvokerClientInterceptor.invoke(HttpInvokerClientInterceptor.java:145)

     at org.springframework.aop.framework.ReflectiveMethodInvocation.proceed(ReflectiveMethodInvocation.java:172)

     at org.springframework.aop.framework.JdkDynamicAopProxy.invoke(JdkDynamicAopProxy.java:202)

     at $Proxy0.executeCommand(Unknown Source)

     at com.rsa.command.CacheableHttpInvokerTarget.executeCommand(HttpInvokerCommandTarget.java:261)

     at com.rsa.command.DelegatingCommandTarget.executeCommand(DelegatingCommandTarget.java:66)

     at com.rsa.command.TargetableCommand.execute(TargetableCommand.java:270)

     at com.rsa.authn.LoginCommand.execute(LoginCommand.java:612)

     at com.rsa.authn.AuthenticatedTargetImpl.login(AuthenticatedTargetImpl.java:161)

     at com.rsa.command.ConnectionFactory$ConnectionImpl.connect(ConnectionFactory.java:754)

     at com.rsa.command.ConnectionFactory.connect(ConnectionFactory.java:542)

     at com.rsa.riat.tools.internal.Utils.login(Utils.java:1050)

     at com.rsa.riat.tools.is.DiscoverIdentitySources.execute(DiscoverIdentitySources.java:81)

     at com.rsa.riat.tools.ConfigureRIATCmd.execute(ConfigureRIATCmd.java:192)

     at com.rsa.riat.tools.ConfigureRIATCmd.main(ConfigureRIATCmd.java:517)

Caused by: org.apache.commons.httpclient.HttpException: Did not receive successful HTTP response: status code = 404, status message = [Not Found]

     at org.springframework.remoting.httpinvoker.CommonsHttpInvokerRequestExecutor.validateResponse(CommonsHttpInvokerRequestExecutor.java:214)

     at org.springframework.remoting.httpinvoker.CommonsHttpInvokerRequestExecutor.doExecuteRequest(CommonsHttpInvokerRequestExecutor.java:131)

     at org.springframework.remoting.httpinvoker.AbstractHttpInvokerRequestExecutor.executeRequest(AbstractHttpInvokerRequestExecutor.java:136)

     at org.springframework.remoting.httpinvoker.HttpInvokerClientInterceptor.executeRequest(HttpInvokerClientInterceptor.java:192)

     at org.springframework.remoting.httpinvoker.HttpInvokerClientInterceptor.executeRequest(HttpInvokerClientInterceptor.java:174)

     at org.springframework.remoting.httpinvoker.HttpInvokerClientInterceptor.invoke(HttpInvokerClientInterceptor.java:142)

     ... 14 more

 

 

If I try to go to that commandserver url in the log above in a browser, it also get a 404:

404.png

 

The only thing similar I can find online is here:

http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=2036170

 

Very similar exception error but nothing similar in my discover-is.log file.

 

From that kb link above I have run the following command:

C:\Program  Files\VMware\Infrastructure\SSOServer\utils>ssocli.cmd configure-riat  -a discover-is -u admin -p <masterPassword>

 

And I get the following output which confirms the discover-is log:


cli.png

Netstat shows that port 7444 is opened by Java and nothing else. The other potential problem port (443) is not in use by anything else that it shouldnt be.

 

I suspect this may be the cause of the problem but I have no idea where to go next. Any suggestions would be greatly appreiciated.

 

Many thanks,

 

Matt


From vCenter 6.0 U1 to U2

$
0
0

I have to update from vCetner 6.0 U1 to U2 because of this security bug http://www.vmware.com/security/advisories/VMSA-2016-0004.html

 

I have an external PSC and a Windows based vCetner 6.

 

I haven't found any official documentation for this update.

 

Is there anything I have to be aware of or it's as simple as running the installer on the Windows vCenter server?

 

Thanks.

Any harm in disabling the VSAN Health Service?

$
0
0

Since updating to vCenter / vSphere 6 update 2, I'm starting to see a steady stream of VSAN Health tasks being logged in vcenter.  However, I'm not using or even licensed for VSAN so I'm a little stumped.  .  The events being logged every few seconds are:

 

     Retrieve a ticket to register the Virtual SAN VASA Provider

and

     Update option values

 

If I stop the VSan Health Monitoring Service, these events stop. 

 

My question is, if I'm not actually using VSAN, is there any harm in disabling the Health Monitor service?  I'm assuming no, but would like to get confirmation

Unable to retreive health data from sps and sms - using vCSA appliance

$
0
0

Hi,

 

I have updated the vCenter 5.5 to the latest version that is available yesterday. It is linux appliance.

 

I was having problem to get in to web client after the update. I performed the "Regenerate SSL certificates" option thats located under Admin tab. Then the issue is resolved and I am able to get in to web client.

 

Now, I am seeing the different issue.

 

Unable to retreive health data from http://localhost/sps/health.xml

Unable to retreive health data from http://localhost/sms/health.xml

 

These 2 services are running but not able to load it. Also, I am seeing the following exceptions in the log.

 

From vpxd log:

--------------------

[7F4D4DD3A700 error 'HttpConnectionPool-000340'] [ConnectComplete] Connect failed to <cs p:00007f4cd40b2850, TCP:vc55mjl1.lab.equallogic.com:10443>; cnx: (null), error: N7Vmacore3Ssl18SSLVerifyExceptionE(SSL Exception: Verification parameters:

--> PeerThumbprint: 36:D5:B5:C2:8B:A5:A6:40:39:10:57:A0:0A:CF:B0:75:1B:62:31:1F

--> ExpectedThumbprint: 06:E3:CB:EB:48:12:59:47:1E:AA:05:69:B0:D5:42:14:AD:5B:63:85

--> ExpectedPeerName:xxxxxxxxxxxx

--> The remote host certificate has these problems:

-->

--> * unable to get local issuer certificate)

 

From vws log:

 

[2014-01-03 22:09:26,979 Thread-21  ERROR com.vmware.vim.health.impl.XmlUtil] Error retrieving health from url: http://localhost/sps/health.xml

java.io.IOException: Server returned HTTP response code: 503 for URL: http://localhost/sps/health.xml

        at sun.net.www.protocol.http.HttpURLConnection.getInputStream(Unknown Source)

        at org.apache.xerces.impl.XMLEntityManager.setupCurrentEntity(Unknown Source)

        at org.apache.xerces.impl.XMLVersionDetector.determineDocVersion(Unknown Source)

        at org.apache.xerces.parsers.XML11Configuration.parse(Unknown Source)

        at org.apache.xerces.parsers.XML11Configuration.parse(Unknown Source)

        at org.apache.xerces.jaxp.validation.StreamValidatorHelper.validate(Unknown Source)

        at org.apache.xerces.jaxp.validation.ValidatorImpl.validate(Unknown Source)

        at javax.xml.validation.Validator.validate(Unknown Source)

        at com.vmware.vim.health.impl.XmlUtil.getDocumentFromUrl(XmlUtil.java:96)

        at com.vmware.vim.health.impl.ComponentSpec.retrieveHealthFromUrl(ComponentSpec.java:300)

        at com.vmware.vim.health.impl.ComponentSpec.retrieveHealth(ComponentSpec.java:266)

        at com.vmware.vim.health.impl.HealthPollerImpl.retrieveHealthFromUrl(HealthPollerImpl.java:119)

        at com.vmware.vim.health.impl.HealthPollerImpl.retrieveHealth(HealthPollerImpl.java:104)

        at com.vmware.vim.health.impl.HealthPollerImpl.computeHealth(HealthPollerImpl.java:203)

        at com.vmware.vim.health.impl.HealthPollerImpl.retrieveHealth(HealthPollerImpl.java:102)

        at com.vmware.vim.health.impl.HealthPollerImpl.pollHealth(HealthPollerImpl.java:85)

        at com.vmware.vim.health.impl.HealthPollerImpl.access$100(HealthPollerImpl.java:28)

        at com.vmware.vim.health.impl.HealthPollerImpl$PollerThread.run(HealthPollerImpl.java:55)

        at java.lang.Thread.run(Unknown Source)

[2014-01-03 22:09:26,979 Thread-21  ERROR com.vmware.vim.health.impl.ComponentSpec] Unable to retrieve health for com.vmware.vim.sps from http://localhost/sps/health.xml

[2014-01-03 22:09:26,979 Thread-21  ERROR com.vmware.vim.health.impl.ComponentSpec] Unable to retrieve health for com.vmware.vim.sps from any of its health URLs

[2014-01-03 22:09:26,981 Thread-21  ERROR com.vmware.vim.health.impl.XmlUtil] Error retrieving health from url: http://localhost/sms/health.xml

java.io.IOException: Server returned HTTP response code: 503 for URL: http://localhost/sms/health.xml

        at sun.net.www.protocol.http.HttpURLConnection.getInputStream(Unknown Source)

        at org.apache.xerces.impl.XMLEntityManager.setupCurrentEntity(Unknown Source)

        at org.apache.xerces.impl.XMLVersionDetector.determineDocVersion(Unknown Source)

        at org.apache.xerces.parsers.XML11Configuration.parse(Unknown Source)

        at org.apache.xerces.parsers.XML11Configuration.parse(Unknown Source)

        at org.apache.xerces.jaxp.validation.StreamValidatorHelper.validate(Unknown Source)

        at org.apache.xerces.jaxp.validation.ValidatorImpl.validate(Unknown Source)

        at javax.xml.validation.Validator.validate(Unknown Source)

        at com.vmware.vim.health.impl.XmlUtil.getDocumentFromUrl(XmlUtil.java:96)

        at com.vmware.vim.health.impl.ComponentSpec.retrieveHealthFromUrl(ComponentSpec.java:300)

        at com.vmware.vim.health.impl.ComponentSpec.retrieveHealth(ComponentSpec.java:266)

        at com.vmware.vim.health.impl.HealthPollerImpl.retrieveHealthFromUrl(HealthPollerImpl.java:119)

        at com.vmware.vim.health.impl.HealthPollerImpl.retrieveHealth(HealthPollerImpl.java:104)

        at com.vmware.vim.health.impl.HealthPollerImpl.computeHealth(HealthPollerImpl.java:203)

        at com.vmware.vim.health.impl.HealthPollerImpl.retrieveHealth(HealthPollerImpl.java:102)

        at com.vmware.vim.health.impl.HealthPollerImpl.pollHealth(HealthPollerImpl.java:85)

        at com.vmware.vim.health.impl.HealthPollerImpl.access$100(HealthPollerImpl.java:28)

        at com.vmware.vim.health.impl.HealthPollerImpl$PollerThread.run(HealthPollerImpl.java:55)

        at java.lang.Thread.run(Unknown Source)

 

 

I have loooked at the hosts file and make sure DNS is right. Also, Performed Regenerate certificates on appliance. Any ideas where to look for to troubleshoot??

 

Appreciated ,

 

Thanks!!

Error 1068 When trying to start vCenter Server Service

$
0
0

i am getting this Error 1068 When trying to start vCenter Server Service. Any Solution for this?

vCenter Appliance (vcsa) 6 can not add a new source identity (Active directory)

$
0
0

Hi every one,

 

i have join the vCenter node to our Domain

vcenter1.png

and reboot the VM appliance vCenter.After that, i check and it's ok vCenter Appliance is join our Active directory domaine Windows Server 2003.

 

Now,i try to add a new source identity, i have an error: Provided credentials are not valid

this is my configuration when i try to add a new source

 

  • identity source type: Active Directory as LDAP Server
  • Name: ourdomain.com
  • Base DN for users: OU=Users,DC=OURDOMAIN,DC=COM
  • Domain name: OURDOMAIN.COM
  • Domain alias: OURDOMAIN
  • Base DN for groups: OU=Users,DC=OURDOMAIN,DC=COM
  • Primary server URL: ldap://DC1.OURDOMAIN.COM:389
  • Secondary server URL:
  • Username: Administrateur@ourdomain.com
  • Password: PasswordofAdministrateur

 

When i click test connection, it's work i have seccuessfuly test but whene i try to add this source i have this error: Provided credentials are not valid


Any one can help me please ?


Best regards

Viewing all 18256 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>