Hi.
I can't login to vCenter with WebClient or old client using my AD accont. VMware support can't help me yet. It breaks after update to vCenter 5.5 Update 3a.
In vmware-sts-idmd.log i see:
2016-01-06 08:08:59,121 ERROR [IdentityManager] Failed to authenticate principal [01AbzalovIV-Adm@REGION] for tenant [vsphere.local]
com.vmware.identity.idm.IDMLoginException: Access denied
at com.vmware.identity.idm.server.IdentityManager.authenticate(IdentityManager.java:2481)
at sun.reflect.GeneratedMethodAccessor24.invoke(Unknown Source)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)
at java.lang.reflect.Method.invoke(Unknown Source)
at sun.rmi.server.UnicastServerRef.dispatch(Unknown Source)
at sun.rmi.transport.Transport$2.run(Unknown Source)
at sun.rmi.transport.Transport$2.run(Unknown Source)
at java.security.AccessController.doPrivileged(Native Method)
at sun.rmi.transport.Transport.serviceCall(Unknown Source)
at sun.rmi.transport.tcp.TCPTransport.handleMessages(Unknown Source)
at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run0(Unknown Source)
at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.access$400(Unknown Source)
at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler$1.run(Unknown Source)
at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler$1.run(Unknown Source)
at java.security.AccessController.doPrivileged(Native Method)
at sun.rmi.transport.tcp.TCPTransport$ConnectionHandler.run(Unknown Source)
at java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)
at java.lang.Thread.run(Unknown Source)
Also there are many errors for domains which have trusts with my domain REGION and DC's of these domains not available for vCenter server (and it is must to be so).
2016-01-06 08:04:40,004 WARN [WinDomainAdapter] Failed to process trust with domain name krasnodar.<myorg>.ru - Failed to get domain controller information for krasnodar.<myorg>.ru (dwError - 1355 - ERROR_NO_SUCH_DOMAIN)
2016-01-06 08:04:40,129 WARN [WinDomainAdapter] Failed to process trust with domain name saratov.<myorg>.ru - Failed to get domain controller information for saratov.<myorg>.ru (dwError - 1355 - ERROR_NO_SUCH_DOMAIN)
2016-01-06 08:04:40,258 WARN [WinDomainAdapter] Failed to process trust with domain name smr.<myorg>.ru - Failed to get domain controller information for smr.<myorg>.ru (dwError - 1355 - ERROR_NO_SUCH_DOMAIN)
...
We try both types of AD Identity Source for SSO, same errors.
vCenter server computer account is in REGION domain. My 01AbzalovIV-Adm user account also in this domain.
vCenter server can't see root AD domain <myorg>.ru by design of our AD.
vCenter server can see only 2 DC's for REGION domain in our AD site.
All works until update to 5.5 Update 3a. I update to 5.5 3a using unistall all components of vCenter and then reinstall them using existing 5.5 Update 2 database.