{"id":389,"date":"2017-03-08T09:28:26","date_gmt":"2017-03-08T16:28:26","guid":{"rendered":"http:\/\/blog.gptnet.net\/?p=389"},"modified":"2017-03-08T09:30:02","modified_gmt":"2017-03-08T16:30:02","slug":"vcenter-server-appliance-6-0-bug-intermediate-authentication-issues-native-platform-error-1765328378","status":"publish","type":"post","link":"http:\/\/blog.gptnet.net\/?p=389","title":{"rendered":"vCenter Server Appliance 6.0 bug &#8211; Intermediate authentication issues &#8211; Native platform error -1765328378"},"content":{"rendered":"<p>Another mysterious bug from VMware &#8211; intermediate authentication failures.<\/p>\n<p><strong>Symptoms:<\/strong> I&#8217;ve noticed some of the backup jobs were failing because Veeam failed to log in to vCenter. If you&#8217;re familiar with Veeam software &#8211; you define backup account per vCenter and not individual jobs. Hence if the account was invalid, didn&#8217;t have permissions it would affect every single job but not some. After troubleshooting I&#8217;ve discovered in vCenter logs was full of unsuccessful login attempts. Once I&#8217;ve contacted VMware support they confirmed to be a bug.<\/p>\n<p><!--more--><br \/>\nFirst you need to enable trace Likewise Agent logging. Log into vCenter Server appliance and run the following command:<br \/>\n<code>\/opt\/likewise\/bin\/lwsm get-log-level<\/code> &#8211; this will show you current logging level. By default it should be set to <strong>info<\/strong>.<br \/>\nNext you need to change log level to <strong>trace<\/strong> and issue login process from application experiencing failure (in my case it was to start Veeam backup job).<br \/>\n<code>\/opt\/likewise\/bin\/lwsm set-log-level trace<\/code><br \/>\nonce done dont forget to change log back to info<br \/>\n<code>\/opt\/likewise\/bin\/lwsm set-log-level info<\/code><\/p>\n<p>Now we can review the following logs:<\/p>\n<p><strong>vpxd:<\/strong><br \/>\n<code>2017-02-21T14:41:19.635Z error vpxd[7F356356A700] [Originator@6876 sub=[SSO] opID=642416a] [UserDirectorySso] AcquireToken exception: N9SsoClient27InvalidCredentialsExceptionE(Authentication failed<br \/>\n: Invalid credentials)<br \/>\n2017-02-21T14:41:19.635Z error vpxd[7F356356A700] [Originator@6876 sub=User opID=642416a] Failed to authenticate user &lt;account@domain.lan&gt;<br \/>\n2017-02-21T14:41:19.910Z info vpxd[7F3563C78700] [Originator@6876 sub=vpxLro opID=task-internal-1-1f9ef85f-9e] [VpxLRO] -- BEGIN task-internal-170142 -- domain-c26 -- AskRefreshDrmRecLro --<\/code><\/p>\n<p><strong>vmafdvmdirclient.log:<\/strong><br \/>\n<code>2017-02-20T16:32:23.247Z:t@140514804360960:ERROR: VmDirSafeLDAPBind to (ldap:\/\/vcenter01.domain.lan:389) failed. SRP(9127)<br \/>\n2017-02-20T16:33:23.111Z:t@140514804360960:ERROR: VmDirSafeLDAPBind to (ldap:\/\/vcenter01.domain.lan:389) failed. SRP(9127)<\/code><\/p>\n<p><strong>vmware-sts-idmd.log:<\/strong><br \/>\n<code>2017-02-21T14:41:19.617Z vsphere.local 0b82b289-a225-442a-b2da-cfde52e3d989 ERROR] [IdentityManager] Failed to authenticate principal [account@domain.lan]. Native platform error [code: -1765328378][null][null]<br \/>\ncom.vmware.identity.interop.idm.IdmNativeException: Native platform error [code: -1765328378][null][null]<br \/>\nat com.vmware.identity.interop.idm.LinuxIdmNativeAdapter.AuthenticateByPassword(LinuxIdmNativeAdapter.java:180)<br \/>\nat com.vmware.identity.idm.server.provider.activedirectory.ActiveDirectoryProvider.authenticate(ActiveDirectoryProvider.java:278)<br \/>\nat com.vmware.identity.idm.server.IdentityManager.authenticate(IdentityManager.java:2760)<br \/>\nat com.vmware.identity.idm.server.IdentityManager.authenticate(IdentityManager.java:9128)<br \/>\nat sun.reflect.GeneratedMethodAccessor31.invoke(Unknown Source)<br \/>\nat sun.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)<br \/>\nat java.lang.reflect.Method.invoke(Unknown Source)<br \/>\nat sun.rmi.server.UnicastServerRef.dispatch(Unknown Source)<\/code><\/p>\n<p><strong>Cause:<\/strong> According to Vmware support, DNS resolution fails from Likewise. They identified and raised and issue #1770325 for this bug. Fix has been included in vCenter Appliance update 3.<br \/>\n<strong>Solution:<\/strong> Install this patch <a href=\"https:\/\/kb.vmware.com\/kb\/2147800\" target=\"_blank\">https:\/\/kb.vmware.com\/kb\/2147800<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Another mysterious bug from VMware &#8211; intermediate authentication failures. Symptoms: I&#8217;ve noticed some of the backup jobs were failing because Veeam failed to log in to vCenter. If you&#8217;re familiar with Veeam software &#8211; you define backup account per vCenter &hellip; <a href=\"http:\/\/blog.gptnet.net\/?p=389\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[84],"tags":[101,100,68,102],"class_list":["post-389","post","type-post","status-publish","format-standard","hentry","category-vmware","tag-101","tag-authentication-issue","tag-bug","tag-native-platform-error-1765328378"],"_links":{"self":[{"href":"http:\/\/blog.gptnet.net\/index.php?rest_route=\/wp\/v2\/posts\/389","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/blog.gptnet.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/blog.gptnet.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/blog.gptnet.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/blog.gptnet.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=389"}],"version-history":[{"count":7,"href":"http:\/\/blog.gptnet.net\/index.php?rest_route=\/wp\/v2\/posts\/389\/revisions"}],"predecessor-version":[{"id":402,"href":"http:\/\/blog.gptnet.net\/index.php?rest_route=\/wp\/v2\/posts\/389\/revisions\/402"}],"wp:attachment":[{"href":"http:\/\/blog.gptnet.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=389"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/blog.gptnet.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=389"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/blog.gptnet.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=389"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}