After Upgrading or Installing vCenter Server U3b or vCenter Server 7.0, lsassd Frequently Core Dumps and Users Fail to Login with Invalid Credentials
Symptoms
Logging in fails for users with invalid credentials.
/var/log/messages shows the following errors for offline domains:
/var/log/messages shows the following errors indicating lsassd has crashed:
/var/core directory has multiple lsassd core files. e.g. core.lsassd.1541
/var/log/messages shows the following errors for offline domains:
2020-01-07T11:08:52.272792+00:00 vCenterFQDN lsassd[48897]: 0x7f3dd0fcb700:Domain 'DomainFQDN' is now offline
2020-01-07T11:08:52.273091+00:00 vCenterFQDN lsassd[48897]: 0x7f3dd0fcb700:Detected domain 'DomainFQDN' offline. Some group information from this domain might be missing.
2020-01-07T11:08:52.273091+00:00 vCenterFQDN lsassd[48897]: 0x7f3dd0fcb700:Detected domain 'DomainFQDN' offline. Some group information from this domain might be missing.
/var/log/messages shows the following errors indicating lsassd has crashed:
2020-01-07T11:07:48.749200+00:00 vCenterFQDN lwsmd: Restarting dead service: lsass (attempt 1/2)
2020-01-07T11:07:48.749840+00:00 vCenterFQDN lwsmd: Starting service: lsass
2020-01-07T11:07:48.749840+00:00 vCenterFQDN lwsmd: Starting service: lsass
/var/core directory has multiple lsassd core files. e.g. core.lsassd.1541
Cause
This issue was introduced in vCenter
Server U3b (15129973) while modifying how likewise handles offline
domains. Likewise can return a partial set of group memberships or none
for any user associated via group membership with a trusted domain in
an offline condition. This issue also impacts vCenter Server 7.0 GA.
Resolution
This issue is resolved in vCenter Server 6.7 U3g. For more details please see the release notes.
This issue is resolved in vCenter Server 7.0b. For more details please see the release notes.
This issue is resolved in vCenter Server 7.0b. For more details please see the release notes.
Workaround
- Login using SSH to an impacted external PSC or embedded VCSA.
- Exclude offline domains by adding to DomainManagerExcludeTrustList.
/opt/likewise/bin/lwregshell
set_value
'[HKEY_THIS_MACHINE\Services\lsass\Parameters\Providers\ActiveDirectory]'
"DomainManagerExcludeTrustsList" "Offline domain FQDN" "Offline domain
FQDN"
For example,
/opt/likewise/bin/lwregshell set_value '[HKEY_THIS_MACHINE\Services\lsass\Parameters\Providers\ActiveDirectory]' "DomainManagerExcludeTrustsList" "NASA1.domain.cloud" "APJ1.domain.cloud"
Note: To gather domains that are offline, refer to messages in the symptoms of this KB (/var/log/messages) or run /opt/likewise/bin/lw-lsa get-status.
For example,
/opt/likewise/bin/lwregshell set_value '[HKEY_THIS_MACHINE\Services\lsass\Parameters\Providers\ActiveDirectory]' "DomainManagerExcludeTrustsList" "NASA1.domain.cloud" "APJ1.domain.cloud"
Note: To gather domains that are offline, refer to messages in the symptoms of this KB (/var/log/messages) or run /opt/likewise/bin/lw-lsa get-status.
- Restart likewise
/opt/likewise/bin/lwsm restart lwreg
- Check if the DomainManagerExcludeTrustsList has the excluded domains added to it in the registry.
/opt/likewise/bin/lwregshell list_values '[HKEY_THIS_MACHINE\Services\lsass\Parameters\Providers\ActiveDirectory]'
- Clear the cache.
/opt/likewise/bin/lw-lsa ad-cache --delete-all
- Try to login with user that was failing.
- Confirm group memberships are correct.
/opt/likewise/bin/lw-lsa list-groups-for-user <username>
Comments
Post a Comment