Resolving Platform Services Controller connection problems
Tags and categories that are used for the management of virtual machine backups are stored and managed on the VMware Platform Services Controller (PSC). To be able to use the tagging feature for data protection, the tag-based data mover node and the IBM Storage Protect vSphere Client plug-in must be able to connect to the Platform Services Controller by using the Single Sign On process.
The Platform Services Controller server hosts the VMware Lookup Service that registers the location of vSphere components and handles the vCenter Single Sign On process.
Symptoms
When connection problems occur, the data mover node cannot complete the Single Sign On process and cannot access the tags and categories in the Platform Services Controller.If the Platform Services Controller cannot be reached, the tag information will not be displayed in the IBM Storage Protect vSphere Client plug-in. Virtual machine backup operations will also fail.
Resolving the problem
Complete the following tasks to diagnose and resolve connectivity problems:- Ensure that the Platform Services Controller host is powered on and accessible over the network.
- Ensure that the VMware Lookup Service is active and accepting connections at the following
address:
https://PSC-FQDN/lookupservice/sdk, where PSC-FQDN is the fully qualified domain name of the Platform Services Controller host. - Ensure that a data mover is installed on the same server that hosts the Data Protection for VMware vSphere GUI. The data mover node must be configured so that the vCenter server credentials are saved, for example, by using the dsmc set password command in the backup-archive command-line.
- On UNIX and Linux®
clients, the existing passwords in the TSM.PWD files are migrated to the new
password store in the same location. For root users, the default location for the password store is
/etc/adsm. For non-root users, the location of the password store is specified
by the passworddir option.
The TSM.PWD file is deleted after the migration.
- Ensure that client option vmchost is set by using the same value and format that was used for the vCenter server field during the installation of Data Protection for VMware. The preferred format for the vCenter server address is the vCenter server's fully qualified domain name (FDQN). Use the vCenter server IP address only if it was used during the registration of the vCenter, although the IP address is not preferred by VMware.
- The system time on the data mover host must be in sync with the system time on the Platform
Services Controller and vCenter. The system time and time zone must be set correctly on all three
systems. Otherwise, a Platform Services Controller connection error occurs. The following message is
typical of this type of error:
ANS2378E Single Sign On login to the vSphere Server failed in function visdkGetSecurityToken - Issue. "The time now Wed Apr 20 21:31:58 UTC 2016 does not fall in the request lifetime interval extended with clock tolerance of 600000 ms: [ Wed Apr 20 16:20:46 UTC 2016; Wed Apr 20 16:50:46 UTC 2016). This might be due to a clock skew problem." - For more information about messages that occurred, see Messages for the IBM Storage Protect vSphere Client plug-in.