Skip to content
  • Home
  • Automation
  • vSphere and ESXi
  • NSX
  • vCloud Director
  • Other Good Stuff
  • About
  • Contact
  • Home Lab
  • Non-Technical Blogs
  • VMworld and VMUG
  • vSphere with Tanzu
  • vRealize Operations
  • vRealize Log Insight
  • vRealize Hyperic
  • VMware Cloud Foundation
  • LinkedIn
    • GitHub
Search
Close

CaptainvOPS

Month: October 2024

Rotating NSX-T Compute Manager Service Accounts Fails in VMware Cloud Foundation 4.x.

October 10, 2024October 11, 2024 CaptainvOPs

Blog Date: October 10, 2024

Hit a frustrating bug that I had been troubleshooting for weeks in a customer’s VMware Cloud Foundation (VCF) 4.x environment, where the SDDC manager was unable to rotate or remediate the svc-{nsxvip-vcenter-fqdn}@vsphere.local service account, that is used to connect the NSX-T to the Compute Manager (vCenter). We could successfully remediate and rotate the service account for the management domain NSX-T, but we could not rotate vi-workload domain NSX-T service account.

In the SDDC UI and operationsmanager.log, we would see an error message similar to:

“Compute manager {wld-vcenter-fqdn} with id {uuid} connection config is invalid. Edit Hostname and provide compute manager credentials.” 

Come to find out, this is a known bug for the 4.x versions of VCF workload domains that use a shared NSX-T configuration. It is believed that there is an SSO passwords sync delay between vCenter Servers that causes this.

I don’t believe there’s a resolution for 4.x versions of VCF, and have not tested in 5.x versions of VCF, but here’s the work around. Are you ready?

  1. Log into SDDC Manager 
  2. Go to Password management section and select service account in vCenter used by NSX-T to rotate
  3. Initiate the task to rotate the password
  4. Wait for the task to fail like in the picture below.

5. Wait 5 to 15 minutes for sync operations on vCenter to complete and then click on RETRY button. (your mileage may vary depending on vCenter activity)


6. Verify task is successful in SDDC Manager. That should do the trick. Otherwise, you might have something else going on and will need to open a ticket with support to investigate further.

On a side note, the “Last Modified” date may not change in the UI, this is another known bug. All we are looking for here is the task to complete successfully.

It doesn’t appear that this account password is stored in the SDDC manager. It is not stored in the usual way that would present the account using the lookup_passwords utility on the SDDC manager.

In my searching, I did happen to come across the following KB to Retrieve the service accounts credentials from SDDC Manager. Even though this shows the svc-{nsxvip-vcenter-fqdn}@vsphere.local service account, it does not provide the password. I digress. Hopefully the above workaround walk-through helps you.

Archive

  • December 2025
  • October 2025
  • June 2025
  • March 2025
  • December 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • January 2024
  • October 2023
  • September 2023
  • August 2023
  • December 2022
  • November 2022
  • September 2022
  • August 2022
  • December 2021
  • June 2021
  • March 2021
  • January 2021
  • November 2020
  • October 2020
  • September 2020
  • July 2020
  • April 2020
  • March 2020
  • January 2020
  • October 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • March 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • September 2017
  • August 2017
  • July 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
Blog at WordPress.com.
Back to top
  • Subscribe Subscribed
    • CaptainvOPS
    • Already have a WordPress.com account? Log in now.
    • CaptainvOPS
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar
 

Loading Comments...
 

You must be logged in to post a comment.