VCF on VxRail:检查 LDAP 状态时 NSX 卡住
Summary: NSX UI 上的基于轻量级目录访问协议 (LDAP) 的 Active Directory 设置正确。NSX 无法完成对 LDAP 设置的检查。该状态会导致它在功能上不可用。
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
NSX UI 上的基于 LDAP 的 Active Directory 设置正确。NSX 无法完成对 LDAP 设置的检查。该状态会导致它在功能上不可用。
LDAP 设置正确,但无法添加新用户。
NSX UI 的 VMware Identity Manager 选项卡上有一个不正常的标记,例如连接断开。
本地主机访问日志:VMware Identity Manager (VIDM) 状态返回 HTTP 代码 400。
nsx-mgr> tail -f /var/log/proxy/localhost_access_log 2024-08-06T02:27:46.690Z - "GET /policy/api/v1/aaa/roles HTTP/1.1" 200 343 13 13 2024-08-06T02:27:46.738Z - "GET /favicon.ico HTTP/1.1" 200 5686 2 1 2024-08-06T02:27:46.811Z - "POST /policy/api/v1/search/aggregate?page_size=250 HTTP/1.1" 200 2026 105 105 2024-08-06T02:27:46.812Z - "POST /policy/api/v1/search/aggregate?page_size=50&cursor=0&sort_by=display_name&sort_ascending=true HTTP/1.1" 200 1306 113 113 2024-08-06T02:27:48.461Z - "GET /api/v1/node/aaa/providers/vidm/status HTTP/1.1" 400 135 1761 1760
Cause
NSX 会在完成之前扫描所有身份上下文。
如果集成了 VMware Identity Manager,并且 NSX 与 VIDM 之间的连接断开,则身份扫描会卡住。
Resolution
修正步骤:
1.从 NSX Manager 检查此错误的详细原因:
curl -k -u 'admin:<nsx admin password>' -X GET https://localhost/api/v1/node/aaa/providers/vidm/status
输出可能类似于以下内容:
"error_message": "Invalid VMware Identity Manager thumbprint specified."
2.检查 VIDM 的当前指纹。
openssl s_client -connect <FQDN of vIDM host>:443 < /dev/null 2> /dev/null | openssl x509 -sha256 -fingerprint -noout -in /dev/stdin
3.在 NSX UI 上替换为正确的指纹并保存。

4.连接状态恢复后,它将显示为“Up”。

Affected Products
VxRail, VxRail Appliance Series, VxRail E560 VCF, VxRail E560F VCF, VxRail E560N VCF, VxRail G560 VCF, VxRail G560F VCF, VxRail P570 VCF, VxRail P570F VCF, VxRail P580N VCF, VxRail S570 VCF, VxRail V570 VCF, VxRail V570F VCFArticle Properties
Article Number: 000227655
Article Type: Solution
Last Modified: 08 Nov 2025
Version: 3
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.