Quantcast
Channel: VMware Communities : Unanswered Discussions - vCenter™ Server
Viewing all 3506 articles
Browse latest View live

VSphere ESX Health status monitoring

$
0
0

Hello,

 

We've a problem with vSphere ESX Agent Manager service.

 

We've alert message: Unable to retrieve health data from https://xxxxxx:443/eam/eamService-web/health.xml

 

The content of xml is:

 

<vimhealthxmlns="http://www.vmware.com/vi/healthservice"xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"schemaVersion="1.0">

 

<healthid="com.vmware.vim.eam">

 

 

<name>vSphere ESX Agent Manager</name>

 

<status>green</status>

 

<healthid="com.vmware.vim.eam.vShield-VXLAN-service">

 

 

<name>com.vmware.vShieldManager</name>

 

<status>red</status>

 

<healthid="com.vmware.vim.eam.vShield-VXLAN-service.not-initialized">

 

 

<name>10.128.1.9</name>

 

<status>red</status>

<messageid="com.vmware.vim.eam.vShield-VXLAN-service.not-initialized.issue0"level="error"time="2019-11-29T13:00:07">XXX uninitialized</message>

</health>

 

<healthid="com.vmware.vim.eam.vShield-VXLAN-service.not-initialized">

 

 

<name>10.128.1.6</name>

 

<status>red</status>

<messageid="com.vmware.vim.eam.vShield-VXLAN-service.not-initialized.issue0"level="error"time="2019-11-29T12:59:04">XXX uninitialized</message>

</health>

 

<healthid="com.vmware.vim.eam.vShield-VXLAN-service.not-initialized">

 

 

<name>10.128.1.8</name>

 

<status>red</status>

<messageid="com.vmware.vim.eam.vShield-VXLAN-service.not-initialized.issue0"level="error"time="2019-11-29T12:59:25">XXX uninitialized</message>

</health>

 

<healthid="com.vmware.vim.eam.vShield-VXLAN-service.not-initialized">

 

 

<name>10.128.1.7</name>

 

<status>red</status>

<messageid="com.vmware.vim.eam.vShield-VXLAN-service.not-initialized.issue0"level="error"time="2019-11-29T12:59:46">XXX uninitialized</message>

</health>

</health>

</health>

</vimhealth>

 

 

The error occurred after a power failure. We tried to restart the server but the alert still appears.

 

To what is due?

 

Thank you

Regards


Query Regarding Updating Vcenter

$
0
0

Hi,

I am currently looking at upgrading our Vcenter. We are currently on 6.5u2f and the latest is 6.5u3e.

 

We went from 5.5 earlier on in the year and had numerous guest VM'S on vmwaretools 9355, which looking at the build numbers points to 5.5 tool version.

 

I was worried initially and updated many of the guests tools. Some are now on 102xx and some 103xx.

 

My question is, will this cause the VM'S an issue having mismatched tool versions when i upgrade Vcenter (especially the ones that were on 9355 originally).

 

Also i presume that Vcenter updates are cumulative. So i can jump straight from 6.5.u2f to 6.5u3e. Or do i have to do incremental upgrade steps?.

 

I hope I'm clear on my concerns, and i am very much grateful to hear from the experts.

 

Thanks guys

Add permission fails with error

$
0
0

We have a newer 6.5 vcenter that I am trying to add a particular user to a particular VM for management but the following error message occurs

 

The "Add permission" operation failed for the entity with the following error message.

Provider method implementation threw unexpected exception: %s

 

All vCenters are 6.5 U3. However two of them this works on have been upgraded from 5.5. Has this type of permission setting been deprecated. If so is their a workaround? Otherwise I'm at a loss. Even setting the permissions from the top down gives me the same error. The only way I can set the permissions is from the "Global Permissions" but I do not want them to even see anything other than what they are allowed

 

Following articles still give me the same error

Assign a User Permissions for a Virtual Machine in the VMware Host Client

Understanding the vCenter Server Permission Model

smartcard and logging in a 2nd time

$
0
0

I'm testing out enabling smart card authentication for vcenter (yubikey specifically) and I managed to get it working but noticed that once I log out (or get logged out automatically), I cannot login again without closing the entire browser.

 

If a user has a bunch of tabs open, it's a bit of a pain.

 

The best I've been able to do is use a private browsing window but that just gets me one more login before I'm stuck again on my next login.

 

Is this just the way things work or is there a way to make this more workable for users?

vCenter License stale entry

$
0
0

I install the 2 vCenter servers 6.7 in link mode with embedded PSC . i break the link mode. now both server are accessible individuals. but under license-> assets still both vcenter and hosts are visible.

 

vcenter server: vcenter server 6.7 appliance with embedded PSC servers, single SSO.

VCSA 6.7 - vpxd doesn't start after replacing machine SSL certs

$
0
0

Creating a new VCSA 6.5.0 vm using win32 GUI.

After installation completed, I want to replace machine SSL certificates using HTML5 webgui.

I imported Terena CA and then replaced machine SSL cert (key & crt). After rebooting, all works fine.

 

 

Deleting this VM, and creating a new VCSA 6.7 VM using win32 GUI and exactly the same paramaters as before (fqdn, ip, ...). DNS entries are ok (FQDN to IP & IP to FQDN).

After installation completed, I imported the same certificate as before. After rebooting, when I try to access the web GUI, I've got the following error :

 

503 Service Unavailable (Failed to connect to endpoint: [N7Vmacore4Http20NamedPipeServiceSpecE:0x00007f3890084700] _serverNamespace = / action = Allow _pipeName =/var/run/vmware/vpxd-webserver-pipe)

 

 

Trying to replace de certificate from CLI using certificate-manager :

Updated 34 service(s)

Status : 70% Completed [stopping services...]

Status : 85% Completed [starting services...]

Error while starting services, please see service-control log for more details

Status : 0% Completed [Operation failed, performing automatic rollback]              

Error while replacing Machine SSL Cert, please see /var/log/vmware/vmcad/certificate-manager.log for more information.

Performing rollback of Machine SSL Cert...

Get site nameus : 0% Completed [Rollback Machine SSL Cert...]    

 

This is the /var/log/vmware/vmcad/certificate-manager.log log :

 

2019-12-06T13:19:16.509Z INFO certificate-manager None

2019-12-06T13:19:26.519Z INFO certificate-manager Running command :- service-control --start  --all

2019-12-06T13:19:26.519Z INFO certificate-manager please see service-control.log for service status

Service-control failed. Error: Failed to start services in profile ALL. RC=2, stderr=Failed to start vpxd services. Error: Service crashed while starting

2019-12-06T13:25:38.27Z ERROR certificate-manager None

 

This is the vpxd.log :

 

--> [context]zKq7AVECAAAAAGC34QANdnB4ZAAA4AArbGlidm1hY29yZS5zbwAAWCUbAP6dGACeQCIAaXEiABtFIgDTSSIAOaIjAHFvIwA6ciMAnVYrAdRzAGxpYnB0aHJlYWQuc28uMAAC3Y4ObGliYy5zby42AA==[/context]

2019-12-06T13:23:09.269Z error vpxd[59800] [Originator@6876 sub=AuthzStorageProvider] [AuthzStorageProvider::CreateAuthzMgr] Failed to connect to IS: <N5Vmomi5Fault17HostCommunication9ExceptionE(Fault cause: vmodl.fault.HostCommunication

--> )

--> [context]zKq7AVECAAAAAGC34QASdnB4ZAAA4AArbGlidm1hY29yZS5zbwAAWCUbAP6dGAHu8VN2cHhkAAHu1VoBzsNjATdPoAGuOKACwO0BbGliYXV0aHpjbGllbnQuc28AAmkGAgLijQICxIUCAb3XngE6CVQBimhUARnGUgOQBQJsaWJjLnNvLjYAAaW+Ug==[/context]>

2019-12-06T13:23:09.270Z info vpxd[59800] [Originator@6876 sub=AuthzStorageProvider] [AuthzStorageProvider::CreateAuthzMgr] Retry for this error: attempt count 29

2019-12-06T13:23:12.314Z warning vpxd[59800] [Originator@6876 sub=VpxdAuthClient] [ConnectAndLogin] Failed to loginBySamlToken: N7Vmacore3Ssl18SSLVerifyExceptionE(SSL Exception: Verification parameters:

--> PeerThumbprint: 6B:B6:1F:29:7C:01:E8:65:09:A1:49:C2:46:71:BC:54:11:FB:7F:A8

--> ExpectedThumbprint:

--> ExpectedPeerName: localhost

--> The remote host certificate has these problems:

-->

--> * Host name does not match the subject name(s) in certificate.)

 

 

I don't know why ExpectedPeerName is searching for localhost, I always used fqdn and real ip during process and DNS is correctly resolving IP address & FQDN.

Either using webgui or cli for replacing the machine certificate, vpxd doesn't launch after.

Are there new prerequisites for installing a custom SSL certificate since 6.7.0 ?

what happens to my VMs if i restart the vsphere web client on windows?

$
0
0

Hi Team

 

I recently upgrade my windows server and ever since cannot see my existing VMs and services.

I can login to the vsphere web client but the clusts and hosts pane takes forever to load and eventually

doesnt load at all.

 

I would like to restart the vsphere web client services on my windows server. will this affect my VMs?

 

hosts clusters no loading.JPG

Vcenter 6.0 locking out AD account

$
0
0

We have an issue where after a password change in AD some of our vcenter users are getting their accounts locked out because vcenter is trying to authenticate against the domain with a bad password, any ideas? I was unable to find anything useful in vpxd.log.


vCenter 6.0 windows to vCenter 6.5 windows upgrade fails with error (UPGRADE_EXPORT_TIMEOUT)

$
0
0

Hello!

 

I try to upgrade my vCenter 6.0 on Windows 2008R2 to 6.5 version.

Upgrade fails with error:

to6.5.png

 

Can anybody help me?

 

System extension in Windows don't help.

UPGRADE_EXPORT_TIMEOUT=600

UPGRADE_IMPORT_TIMEOUT=600

Random Domain User authentication failure

$
0
0

Im having a randomly occurring event with the domain admin, which is part of Administrators group on vCentre. Attempting to login to the web console with " domain.local\Administrator" or "domain\Administrator" will intermittently fail. Even using the authenticator plugin, it will fail on authentication sometimes. It varies which one will work "domain.local\" or "domain\", also both may fail but the authenticator application will allow login (which shows the "domain\") being used. Adding to that, log out, and try with the method that failed before, and it will work.

 

This is not computer specific either, trying on a vm running inside the vm environment, a laptop, another desktop. Only thing common is this is using the web console in chrome. DNS does not seem to be an issue on the network. Looking in the events for the Datacentre in vm web console, i see no authentication errors.

 

Another issue which I'm sure has to do with this in some way, Veeam backups run over night and will fail halfway through with authentication failure trying to snapshot VM's. In an attempt to try and get successful backups, I broke the backups down; one at 2200HRS and another later at 0400HRS. The 2200HRS backup failed halfway through with authentication issues, the 0400HRS backup proceeded successfully, having only one VM to backup.

 

I dont know what would be causing these authentication issues, and whats further stranger, is how "domain.local\" wont work but when specifying "domain\" will work, or vice versa. This issue has been a recent one, only starting within the last 2 months.

 

At no time has the domain admin account in use here ever been locked out, password does not expire.

 

vCentre 6.7 Build 11727113

ESXi 6.7 Build 10302608

VMWare Hybernate

$
0
0

dear All,

 

I configure redundant Servers using ESXI 6.0; The Redundant Server is a DCS Server (DCS = Distributed Control System); which the redundant is managed by DCS Software. The DCS Software is configured under VM (VM-DCS01 = Primary, VM-DCS02 = Secondary). Sometime the secondary VM-DCS02 is failed to synchronize with primary VM-DCS01. I have check that the VM-DCS01 cannot ping to VM-DCS02 then I try to remote to VM-DCS02 using VMWare Workstation. After few minutes the VM-DCS02 is synchronize with primary VM-DCS01.

 

It seems that the Secondary VM-DCS02 is in "Sleep/Hybernate" mode and "Wake" after remote to VM-DCS02. Is there any configuration that i missed at ESXI.

 

Please advise.

 

Thank Tou

VCSA lit up like a xmas tree after upgrading to 6.7.0.42000

$
0
0

Every powered on item (hosts, clusters and VMs) has either a red or orange warning. I saw on Reddit that this was due to the ImageBuilder service not running. I looked and it was not running. Even after starting the service, the warnings remain.

vcenter error

$
0
0

hi all

vcenter keeps displaying this error at the installation of stage 2 what did I do wrong please anyone help "Could not connect to VMware Directory Service via LDAP. Verify VMware Directory Service is running on the appropriate system and is reachable from this host."

vcenter error

$
0
0

hi all

I am trying to deploy vcenter 6.7 without an actual DNS server I give vcenter my gateway IP address as a DNS server and also fill the FQDN with my vcenter IP address and now I am facing the error saying "Error occurred while starting services 'vpxd-svcs' what should I do please?

VCSA 6.7 U2 Converge failure

$
0
0

I have a separate PSC and VCSA at version 6.5 U2.  I have upgraded both to version 6.7 U2 from the ISO and am now trying to converge to one VM.  I have mounted the VCSA ISO on the VCSA 6.7 VM as I don't have internet access from these machines.  The converge process is started succesfully from the GUI but then fails.  looking at the converge.log on the VCSA I see the first error is 'ERROR converge Unable to run ldapsearch'

then it later says 'ERROR converge Failed to run white listed firstboot scripts'

 

I have checked the converge_status.json file and it indicates firstboot stage 1 of 4 failed.

 

All DNS is working correctly and I am unsure what to check next with this.  It is a lab environment so I can try things out without affecting any prod systems.  Any suggestions on how to resolve this?

 

Thanks

 

Chris


Converge to Embedded v6.7u3 ui : failed on firstboot

$
0
0

I try to do the convergence from the web UI with 6.7.0.40000 Build 14367737

I have a couple of VCS/PSC on two sites and replication between each PSC

The process succed on first couple, the second failed on step below

 

        {

            "key": "firstbootpart1",

            "value": {

                "description": "Run vmafd firstboot",

                "status": "FAILED"

            }

        },

I think i'm exactly in that case : VMware Knowledge Base

so I disable TSO and GSO as explained on both PSC (source and replicat embedded previously converged)

But know, how can I restart the process ? should I restore backup ?

Another question, since the first converge succeed I haven't yet decommission it, I expect to do that after full convergence, but doesn't know the best practice.

 

converge.log

 

2019-10-10T12:28:28.18Z INFO converge Validating Provided Configuration ...

2019-10-10T12:28:28.23Z INFO converge Running the ldapsearch

2019-10-10T12:28:28.23Z INFO converge Running command: ['/opt/likewise/bin/ldapsearch', '-h', 'llivmwpsc01.my.domain.lan', '-w', '******', '-x', '-D', 'cn=administrator,cn=users,dc=vsphere,dc=local', '-b', 'cn=Sites,cn=Configuration,dc=vsphere,dc=local']

2019-10-10T12:28:28.238Z INFO converge Running command ldapsearch successful

2019-10-10T12:28:28.282Z INFO converge Following solutions have been found registered to the Platform Services Controller. You may have to re-register these after convergence. Please refer to the documentation for details.

2019-10-10T12:28:29.134Z INFO converge Infra node url https://llivmwpsc01.my.domain.lan:443/sts/STSService/ is up

2019-10-10T12:28:29.205Z INFO converge Infra node url https://llivmwpsc01.my.domain.lan:443/idm/ is up

2019-10-10T12:28:29.327Z INFO converge Verify AD domain input info.

2019-10-10T12:28:29.327Z INFO converge Skipping AD Domain related checks.

2019-10-10T12:28:29.331Z INFO converge Validation completed successfully.

2019-10-10T12:28:31.384Z INFO converge Validating Provided Configuration ...

2019-10-10T12:28:31.391Z INFO converge Running the ldapsearch

2019-10-10T12:28:31.392Z INFO converge Running command: ['/opt/likewise/bin/ldapsearch', '-h', 'llivmwpsc01.my.domain.lan', '-w', '******', '-x', '-D', 'cn=administrator,cn=users,dc=vsphere,dc=local', '-b', 'cn=Sites,cn=Configuration,dc=vsphere,dc=local']

2019-10-10T12:28:31.639Z INFO converge Running command ldapsearch successful

2019-10-10T12:28:31.684Z INFO converge Following solutions have been found registered to the Platform Services Controller. You may have to re-register these after convergence. Please refer to the documentation for details.

2019-10-10T12:28:32.364Z INFO converge Collected start_time:1570710512.3636036 as a part of Telemetry

2019-10-10T12:28:32.366Z INFO converge Collected build_no:14367737 as a part of Telemetry

2019-10-10T12:28:32.366Z INFO converge Collected version:6.7.0.40000 as a part of Telemetry

2019-10-10T12:28:32.367Z INFO converge Collected client:cli as a part of Telemetry

2019-10-10T12:28:32.367Z INFO converge Collected replication_flag:False as a part of Telemetry

2019-10-10T12:28:32.383Z DEBUG converge Starting new HTTPS connection (1): localhost

2019-10-10T12:28:33.75Z DEBUG converge https://localhost:443 "POST /rest/com/vmware/cis/session HTTP/1.1" 200 None

2019-10-10T12:28:33.88Z DEBUG converge Starting new HTTPS connection (1): localhost

2019-10-10T12:28:34.92Z DEBUG converge https://localhost:443 "GET /rest/vcenter/topology/nodes HTTP/1.1" 200 None

2019-10-10T12:28:34.95Z INFO converge Collected noOfVCs:2 as a part of Telemetry

2019-10-10T12:28:34.96Z INFO converge Collected noOfPSCs:2 as a part of Telemetry

2019-10-10T12:28:34.96Z INFO converge Collected topology info as a part of Telemetry

2019-10-10T12:28:34.185Z INFO converge Infra node url https://llivmwpsc01.my.domain.lan:443/sts/STSService/ is up

2019-10-10T12:28:34.224Z INFO converge Infra node url https://llivmwpsc01.my.domain.lan:443/idm/ is up

2019-10-10T12:28:34.326Z INFO converge Verify AD domain input info.

2019-10-10T12:28:34.326Z INFO converge Skipping AD Domain related checks.

2019-10-10T12:28:34.330Z INFO converge Validation completed successfully.

2019-10-10T12:28:34.330Z INFO converge Setting the converge running flag

2019-10-10T12:28:34.347Z INFO converge Running converge on Management node.

2019-10-10T12:28:34.348Z INFO converge Executing reconfiguring steps. This will take few minutes to complete.

Please wait ...

2019-10-10T12:28:34.348Z INFO converge Downloading RPMs

2019-10-10T12:28:34.349Z INFO converge Collected client:rest as a part of Telemetry

2019-10-10T12:28:34.418Z INFO converge Custom URL repositry not configured.Use default VMware repository URL.

2019-10-10T12:28:34.421Z INFO converge  currentURL = https://vapp-updates.vmware.com/vai-catalog/valm/vmw/8d167796-34d5-4899-be0a-6daade4005a3/6.5.0.14000.latest/

2019-10-10T12:28:34.421Z INFO converge Manifest file = https://vapp-updates.vmware.com/vai-catalog/valm/vmw/8d167796-34d5-4899-be0a-6daade4005a3/6.5.0.14000.latest/manifest/manifest-latest.xml

2019-10-10T12:28:34.422Z INFO converge Running command: ['/usr/bin/wget', '--no-check-certificate']

2019-10-10T12:28:34.545Z INFO converge Downloaded file manifest-latest.xml

2019-10-10T12:28:34.546Z INFO converge Running command: ['/usr/bin/wget', '--no-check-certificate']

2019-10-10T12:28:35.73Z INFO converge Exception in downloading file : manifest-latest.xml.sha256

2019-10-10T12:28:35.91Z INFO converge Unsetting the converge running flag

2019-10-10T12:28:38.199Z INFO converge Cleanup successful with partial flag = True.

2019-10-10T12:28:38.201Z INFO converge Collected end_time:1570710518.2011995 as a part of Telemetry

2019-10-10T12:28:38.201Z INFO converge Collected status:False as a part of Telemetry

2019-10-10T12:28:38.202Z INFO converge Collected @type:convergence_telemetry as a part of Telemetry

2019-10-10T12:28:38.213Z DEBUG converge Starting new HTTP connection (1): localhost

2019-10-10T12:28:38.227Z DEBUG converge http://localhost:15080 "POST /analytics/telemetry/ph/api/hyper/send?_c=vcebc.1_0 HTTP/1.1" 201 0

2019-10-10T12:28:38.232Z DEBUG converge Pushed the Collected Data to VMWare Analytics Service as a part of  Telemetry

2019-10-10T14:16:53.773Z INFO converge Validating Provided Configuration ...

2019-10-10T14:16:53.778Z INFO converge Running the ldapsearch

2019-10-10T14:16:53.778Z INFO converge Running command: ['/opt/likewise/bin/ldapsearch', '-h', 'llivmwpsc01.my.domain.lan', '-w', '******', '-x', '-D', 'cn=administrator,cn=users,dc=vsphere,dc=local', '-b', 'cn=Sites,cn=Configuration,dc=vsphere,dc=local']

2019-10-10T14:16:53.990Z INFO converge Running command ldapsearch successful

2019-10-10T14:16:54.37Z INFO converge Following solutions have been found registered to the Platform Services Controller. You may have to re-register these after convergence. Please refer to the documentation for details.

2019-10-10T14:16:58.512Z WARNING converge Unable to query solution regiestered

2019-10-10T14:16:58.638Z INFO converge Infra node url https://llivmwpsc01.my.domain.lan:443/sts/STSService/ is up

2019-10-10T14:16:58.675Z INFO converge Infra node url https://llivmwpsc01.my.domain.lan:443/idm/ is up

2019-10-10T14:16:58.767Z ERROR converge Failed to validate sso credential. Error SoapException:

faultcode: ns0:FailedAuthentication

faultstring: Invalid credentials

faultxml: <?xml version='1.0' encoding='UTF-8'?><S:Envelope xmlns:S="http://schemas.xmlsoap.org/soap/envelope/"><S:Body><S:Fault xmlns:ns4="http://www.w3.org/2003/05/soap-envelope"><faultcode xmlns:ns0="http://docs.oasis-open.org/ws-sx/ws-trust/200512">ns0:FailedAuthentication</faultcode><faultstring>Invalid credentials</faultstring></S:Fault></S:Body></S:Envelope>

2019-10-10T14:16:58.767Z ERROR converge SSO validation failed..

2019-10-10T14:16:58.773Z ERROR converge Pre-checks failed for converge.

2019-10-10T14:16:58.782Z INFO converge Unsetting the converge running flag

2019-10-10T14:17:02.816Z INFO converge Cleanup successful with partial flag = True.

2019-10-10T14:17:35.329Z INFO converge Validating Provided Configuration ...

2019-10-10T14:17:35.334Z INFO converge Running the ldapsearch

2019-10-10T14:17:35.334Z INFO converge Running command: ['/opt/likewise/bin/ldapsearch', '-h', 'llivmwpsc01.my.domain.lan', '-w', '******', '-x', '-D', 'cn=administrator,cn=users,dc=vsphere,dc=local', '-b', 'cn=Sites,cn=Configuration,dc=vsphere,dc=local']

2019-10-10T14:17:35.596Z INFO converge Running command ldapsearch successful

2019-10-10T14:17:35.689Z INFO converge Following solutions have been found registered to the Platform Services Controller. You may have to re-register these after convergence. Please refer to the documentation for details.

2019-10-10T14:17:36.639Z INFO converge Infra node url https://llivmwpsc01.my.domain.lan:443/sts/STSService/ is up

2019-10-10T14:17:36.675Z INFO converge Infra node url https://llivmwpsc01.my.domain.lan:443/idm/ is up

2019-10-10T14:17:36.763Z INFO converge Running command: ['/opt/likewise/bin/ldapsearch', '-h', 'llivmwpsc01.my.domain.lan', '-w', '******', '-x', '-D', 'cn=administrator,cn=users,dc=vsphere,dc=local', '-b', 'cn=LNIVMWVCT01.my.domain.lan,ou=Domain Controllers,dc=vsphere,dc=local']

2019-10-10T14:17:36.782Z INFO converge Replication partner provided is correct.

2019-10-10T14:17:36.783Z INFO converge Verify AD domain input info.

2019-10-10T14:17:36.784Z INFO converge Skipping AD Domain related checks.

2019-10-10T14:17:36.787Z INFO converge Validation completed successfully.

2019-10-10T14:17:38.940Z INFO converge Validating Provided Configuration ...

2019-10-10T14:17:38.949Z INFO converge Running the ldapsearch

2019-10-10T14:17:38.949Z INFO converge Running command: ['/opt/likewise/bin/ldapsearch', '-h', 'llivmwpsc01.my.domain.lan', '-w', '******', '-x', '-D', 'cn=administrator,cn=users,dc=vsphere,dc=local', '-b', 'cn=Sites,cn=Configuration,dc=vsphere,dc=local']

2019-10-10T14:17:39.195Z INFO converge Running command ldapsearch successful

2019-10-10T14:17:39.297Z INFO converge Following solutions have been found registered to the Platform Services Controller. You may have to re-register these after convergence. Please refer to the documentation for details.

2019-10-10T14:17:40.169Z INFO converge Collected start_time:1570717060.1686823 as a part of Telemetry

2019-10-10T14:17:40.171Z INFO converge Collected build_no:14367737 as a part of Telemetry

2019-10-10T14:17:40.172Z INFO converge Collected version:6.7.0.40000 as a part of Telemetry

2019-10-10T14:17:40.172Z INFO converge Collected client:cli as a part of Telemetry

2019-10-10T14:17:40.173Z INFO converge Collected replication_flag:False as a part of Telemetry

2019-10-10T14:17:40.188Z DEBUG converge Starting new HTTPS connection (1): localhost

2019-10-10T14:17:41.12Z DEBUG converge https://localhost:443 "POST /rest/com/vmware/cis/session HTTP/1.1" 200 None

2019-10-10T14:17:41.26Z DEBUG converge Starting new HTTPS connection (1): localhost

2019-10-10T14:17:42.864Z DEBUG converge https://localhost:443 "GET /rest/vcenter/topology/nodes HTTP/1.1" 200 None

2019-10-10T14:17:42.867Z INFO converge Collected noOfVCs:1 as a part of Telemetry

2019-10-10T14:17:42.868Z INFO converge Collected noOfPSCs:2 as a part of Telemetry

2019-10-10T14:17:42.868Z INFO converge Collected topology info as a part of Telemetry

2019-10-10T14:17:42.954Z INFO converge Infra node url https://llivmwpsc01.my.domain.lan:443/sts/STSService/ is up

2019-10-10T14:17:42.991Z INFO converge Infra node url https://llivmwpsc01.my.domain.lan:443/idm/ is up

2019-10-10T14:17:43.70Z INFO converge Running command: ['/opt/likewise/bin/ldapsearch', '-h', 'llivmwpsc01.my.domain.lan', '-w', '******', '-x', '-D', 'cn=administrator,cn=users,dc=vsphere,dc=local', '-b', 'cn=LNIVMWVCT01.my.domain.lan,ou=Domain Controllers,dc=vsphere,dc=local']

2019-10-10T14:17:43.92Z INFO converge Replication partner provided is correct.

2019-10-10T14:17:43.93Z INFO converge Verify AD domain input info.

2019-10-10T14:17:43.94Z INFO converge Skipping AD Domain related checks.

2019-10-10T14:17:43.99Z INFO converge Validation completed successfully.

2019-10-10T14:17:43.100Z INFO converge Setting the converge running flag

2019-10-10T14:17:43.119Z INFO converge Running converge on Management node.

2019-10-10T14:17:43.120Z INFO converge Executing reconfiguring steps. This will take few minutes to complete.

Please wait ...

2019-10-10T14:17:43.120Z INFO converge Downloading RPMs

2019-10-10T14:17:43.121Z INFO converge Collected client:rest as a part of Telemetry

2019-10-10T14:17:43.169Z INFO converge VCSA ISO is mounted. Copying RPMs from the ISO.

2019-10-10T14:17:43.180Z INFO converge ISO version : VMware-vCenter-Server-Appliance-6.7.0.40000-14367737

2019-10-10T14:17:43.180Z INFO converge VC version : VMware-vCenter-Server-Appliance-6.7.0.40000-14367737

2019-10-10T14:17:48.89Z INFO converge Collected site_guid:af685cec-89f9-4dca-872c-1b40c56be288 as a part of Telemetry

2019-10-10T14:17:48.90Z DEBUG converge e5dd6353-547d-4ecc-b908-1cc1a2156dab

2019-10-10T14:17:48.126Z DEBUG converge e4729eae-0fc8-451a-889f-20d1b60d49d7

2019-10-10T14:17:48.465Z INFO converge Store all vecs certificates.

2019-10-10T14:17:49.311Z INFO converge final json ---->

2019-10-10T14:17:49.312Z INFO converge [{'entries': [{'Entry type': 'Private Key', 'Alias': '__MACHINE_CERT', 'cert_path': '/root/velma/old_certs/__MACHINE_CERT-MACHINE_SSL_CERT.crt', 'key_path': '/root/velma/old_certs/__MACHINE_CERT-MACHINE_SSL_CERT.key'}], 'store_name': 'MACHINE_SSL_CERT', 'Number of entries in store': '1'}, {'entries': [{'Entry type': 'Private Key', 'Alias': 'machine', 'cert_path': '/root/velma/old_certs/machine-machine.crt', 'key_path': '/root/velma/old_certs/machine-machine.key'}], 'store_name': 'machine', 'Number of entries in store': '1'}, {'entries': [{'Entry type': 'Private Key', 'Alias': 'vsphere-webclient', 'cert_path': '/root/velma/old_certs/vsphere-webclient-vsphere-webclient.crt', 'key_path': '/root/velma/old_certs/vsphere-webclient-vsphere-webclient.key'}], 'store_name': 'vsphere-webclient', 'Number of entries in store': '1'}, {'entries': [{'Entry type': 'Private Key', 'Alias': 'vpxd', 'cert_path': '/root/velma/old_certs/vpxd-vpxd.crt', 'key_path': '/root/velma/old_certs/vpxd-vpxd.key'}], 'store_name': 'vpxd', 'Number of entries in store': '1'}, {'entries': [{'Entry type': 'Private Key', 'Alias': 'vpxd-extension', 'cert_path': '/root/velma/old_certs/vpxd-extension-vpxd-extension.crt', 'key_path': '/root/velma/old_certs/vpxd-extension-vpxd-extension.key'}], 'store_name': 'vpxd-extension', 'Number of entries in store': '1'}, {'entries': [{'Entry type': 'Private Key', 'Alias': 'sms_self_signed', 'cert_path': '/root/velma/old_certs/sms_self_signed-SMS.crt', 'key_path': '/root/velma/old_certs/sms_self_signed-SMS.key'}], 'store_name': 'SMS', 'Number of entries in store': '1'}, {'entries': [], 'store_name': 'APPLMGMT_PASSWORD', 'Number of entries in store': '0'}, {'entries': [{'Entry type': 'Private Key', 'Alias': 'data-encipherment', 'cert_path': '/root/velma/old_certs/data-encipherment-data-encipherment.crt', 'key_path': '/root/velma/old_certs/data-encipherment-data-encipherment.key'}], 'store_name': 'data-encipherment', 'Number of entries in store': '1'}]

2019-10-10T14:17:49.505Z INFO converge Removing computer account of vCenter on Management node.

2019-10-10T14:17:49.506Z INFO converge Running command: ['/usr/lib/vmware-vmafd/bin/domainjoin', 'leave', '--username', 'administrator', '--password', '******']

2019-10-10T14:17:49.745Z INFO converge Removed vCenter computer account from management node.

2019-10-10T14:17:49.757Z INFO converge Running Firstboots for : vmafd-firstboot

2019-10-10T14:17:59.437Z INFO converge Stopping the services ...

2019-10-10T14:17:59.445Z INFO converge <class 'list'>

2019-10-10T14:17:59.446Z INFO converge ['vmware-certificatemanagement', 'vmware-pod', 'vmware-topologysvc', 'vmware-updatemgr', 'vmware-vcha', 'vmcam', 'vmware-postgres-archiver', 'vsan-dps', 'vmware-perfcharts', 'vmware-vsan-health', 'vsphere-ui', 'vmware-eam', 'vmware-imagebuilder', 'vmware-mbcs', 'vmware-netdumper', 'vmware-rbd-watchdog', 'vmware-vsm', 'vsphere-client', 'vmware-content-library', 'vmware-sps', 'vmware-vpxd', 'vmware-vpxd-svcs', 'vmware-vpostgres']

2019-10-10T14:17:59.446Z INFO converge Stopping services

2019-10-10T14:20:25.24Z INFO converge Stopped all the services.

2019-10-10T14:20:25.54Z INFO converge Removed Old Afd db.

2019-10-10T14:20:25.68Z INFO converge Cleared old ssl certificates.

2019-10-10T14:20:25.252Z INFO converge

2019-10-10T14:20:25.253Z INFO converge Installing PSC Rpms.

2019-10-10T14:20:25.253Z INFO converge Installing rpm: /root/velma/rpm/vmware-directory-6.7.0.4837-14192624.x86_64.rpm

2019-10-10T14:20:26.240Z INFO converge Installing rpm: /root/velma/rpm/vmware-certificate-server-6.7.0.5602-14192633.x86_64.rpm

2019-10-10T14:20:27.128Z INFO converge Installing rpm: /root/velma/rpm/vmware-psc-health-6.7.0.1949-14192626.x86_64.rpm

2019-10-10T14:20:27.494Z INFO converge Installing rpm: /root/velma/rpm/VMware-cis-license-6.7.0-13714356.x86_64.rpm

2019-10-10T14:20:28.220Z INFO converge Installing rpm: /root/velma/rpm/vmware-identity-sts-6.7.0.6011-14192627.noarch.rpm

2019-10-10T14:20:35.690Z INFO converge Installing rpm: /root/velma/rpm/vmware-dns-server-1.0.0-14192631.x86_64.rpm

2019-10-10T14:20:36.509Z INFO converge PSC Rpms Installed Success.

2019-10-10T14:20:36.510Z INFO converge Running the ldapsearch

2019-10-10T14:20:36.511Z INFO converge Running command: ['/opt/likewise/bin/ldapsearch', '-h', 'llivmwpsc01.my.domain.lan', '-w', '******', '-x', '-D', 'cn=administrator,cn=users,dc=vsphere,dc=local', '-b', 'cn=ConsentConfigContainer,cn=PhoneHome,cn=Services,dc=vsphere,dc=local']

2019-10-10T14:20:36.532Z INFO converge Running command successful

2019-10-10T14:20:36.533Z INFO converge CEIP is disabled.

2019-10-10T14:20:36.533Z INFO converge Setting Install Parameters

2019-10-10T14:20:36.543Z INFO converge Install Parameters Set.

2019-10-10T14:20:37.664Z INFO converge Perform update startuptype operation in start order. startup_type=Automatic, svc_names=['vmdird', 'vmcad', 'vmdnsd', 'vmware-sts-idmd', 'vmware-certificatemanagement'], include_vmonsvcs=False include_coreossvcs=False, include_leafossvcs=False

2019-10-10T14:20:37.979Z INFO converge Successfully changed startuptype for service vmdird

2019-10-10T14:20:38.441Z INFO converge Successfully changed startuptype for service vmcad

2019-10-10T14:20:39.9Z INFO converge Successfully changed startuptype for service vmware-sts-idmd

2019-10-10T14:20:39.582Z INFO converge Successfully changed startuptype for service vmdnsd

2019-10-10T14:20:39.601Z INFO converge Successfully changed startuptype for service certificatemanagement

2019-10-10T14:20:39.605Z INFO converge Collected replication_flag:True as a part of Telemetry

2019-10-10T14:20:39.606Z INFO converge Running command: ['/opt/likewise/bin/ldapsearch', '-h', 'LNIVMWVCT01.my.domain.lan', '-w', '******', '-x', '-D', 'cn=administrator,cn=users,dc=vsphere,dc=local', '-b', 'cn=slivctapp.my.domain.lan,ou=Computers,dc=vsphere,dc=local']

2019-10-10T14:20:39.677Z WARNING converge Unable to run ldapsearch

2019-10-10T14:20:39.678Z INFO converge Collected replication_latency:0.0727686882019043 as a part of Telemetry

2019-10-10T14:20:39.678Z INFO converge Leave fed is complete

2019-10-10T14:20:39.679Z INFO converge Leave fed complete status: True

2019-10-10T14:20:39.679Z INFO converge Running Firstboots for : visl-support-firstboot,vmafd-firstboot

2019-10-10T14:26:37.832Z ERROR converge Failed to run white listed firstboot scripts. Error: {

    "problemId": null,

    "detail": [

        {

            "id": "install.ciscommon.command.errinvoke",

            "args": [

                "Command: ['run-firstboot-scripts', '--action', 'firstboot', '--subaction', 'firstboot', '--fbWhiteList', 'visl-support-firstboot,vmafd-firstboot']\nStderr: "

            ],

            "translatable": "An error occurred while invoking external command : '%(0)s'",

            "localized": "An error occurred while invoking external command : 'Command: ['run-firstboot-scripts', '--action', 'firstboot', '--subaction', 'firstboot', '--fbWhiteList', 'visl-support-firstboot,vmafd-firstboot']\nStderr: '"

        }

    ],

    "componentKey": null,

    "resolution": null

}

2019-10-10T14:26:37.849Z INFO converge Unsetting the converge running flag

2019-10-10T14:26:42.103Z INFO converge Cleanup successful with partial flag = True.

2019-10-10T14:26:42.104Z INFO converge Collected end_time:1570717602.1046734 as a part of Telemetry

2019-10-10T14:26:42.105Z INFO converge Collected status:False as a part of Telemetry

2019-10-10T14:26:42.105Z INFO converge Collected @type:convergence_telemetry as a part of Telemetry

2019-10-10T14:26:42.118Z DEBUG converge Starting new HTTP connection (1): localhost

2019-10-10T14:26:42.130Z DEBUG converge http://localhost:15080 "POST /analytics/telemetry/ph/api/hyper/send?_c=vcebc.1_0 HTTP/1.1" 201 0

2019-10-10T14:26:42.133Z DEBUG converge Pushed the Collected Data to VMWare Analytics Service as a part of  Telemetry

 

Thanks for your help

impossible d’accéder a mes hotes et vms depuis vcenter

$
0
0

bonjour,

 

je rencontre un souci dans mon vcenter, je n'ai plus qu'un seul hôte qui s'affiche avec une seule vm (alors que cet hôte en a 4)

lorsque je me connecte directement sur l'esx1, je vois bien toutes les vms.

je ne peux pas supprimer les hôtes pour les remettre ensuite car le menu est grisé.

avez vous déjà rencontré ce souci ? merci pour votre aide.

Change ip vCenter 6.7

$
0
0
Is there a way to change the vcenter ip if during vcenter installation on the FQDN part the vcenter ip was inserted?

Error trying to join AD, error code [40188] | LW_ERROR_UNKNOWN [code 0x00009cfc]

$
0
0

Greetings everyone,

 

We recently set up an complete VM-Ware environment at one of our customers. Initially everything was working fine after set up. Today our customer called in, reporting login issues via Horizon Client.

 

Issue is due to the vCenter SSO -> Invalid Credentials supplied.

 

To solve the issue, we tried to (re)join the vCenter to the domain which fails:

 

Idm client exception: Error trying to join AD, error code [40188]

 

 

We also tried to join via CLI. This results in same Error: LW_ERROR_UNKNOWN [code 0x00009cfc]

 

The active directory tab in SSO configuration screen is showing the correct domain from the initial setup:

Unbenannt.PNG

But with footnote: "The node has not joined any Active Directory yet"

 

 

domainjoin-cli query will also show, that the vCenter is not part of a Domain:

root@gaetckevcapp01 [ ~ ]# /opt/likewise/bin/domainjoin-cli query

Name = gaetckevcapp01

Domain =

Any ideas on how to fix this issue?

vCenter 6.7 generating ICMP port unreachable for DNS query responses

$
0
0

Hello folks,

 

I have two installations with vCenter installed on them that are both doing something that seems peculiar.  They send DNS queries from the vCenter IP address to the assigned DNS servers.  Roughly 15% of the time, they will generate a query the same second with the same source port to both the primary and secondary DNS servers.  When this happens, the firewall logs that the vCenter server responds to the secondary DNS server's answer with an ICMP type 3 code 3 (port unreachable).  This clearly shouldn't be happening (the query to the secondary DNS server probably shouldn't even be happening).  Any ideas on why this would occur?

 

vCenter Server with an embedded Platform Services Controller

v6.7.0.30000

Build 13010631

 

Example firewall log entries:

access-list vm_interface_access_in permitted udp vm-interface/10.1.1.5(33201) -> dc_interface/10.1.3.1(53)

access-list vm_interface_access_in permitted udp vm-interface/10.1.1.5(33201) -> dc_interface/10.1.3.2(53)

No matching connection for ICMP error message:  icmp src vm_interface:10.1.1.5 dst dc_interface:10.1.3.2 (type 3, code 3) on vm_interface.  Original IP payload:  udp src 10.1.3.2/53 dst 10.1.1.5/33201.

 

Thank you!

Viewing all 3506 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>