Resolving Privilege Issues in vCenter Server 8.0U2

Introduction

Upgrading to the latest version of any software can sometimes introduce unexpected challenges. For administrators of VMware vCenter Server 8.0U2, one such issue is the appearance of privilege-related warnings in the vSphere Client. These warnings can cause concern but can be managed with the right steps.

Symptoms

After upgrading to vCenter Server 8.0U2, administrators may encounter the following warning in the vSphere Client’s Events tab: “Privilege check failed for user VSPHERE.LOCAL\vmware-vsm-… for missing permission Sessions.TerminateSession.”

This warning is flagged when the system checks the permissions associated with the VsmSvcRole role assigned to the solution user account.

Cause

The core of this issue lies in the permissions set for the VsmSvcRole. Despite having several default privileges, it lacks the “Sessions.TerminateSession” permission, which is crucial for certain administrative operations within the vSphere environment.

Immediate Workaround

Until VMware releases an update to address this issue, administrators can manually adjust the role permissions to prevent these warnings. Here’s how to implement this workaround:

  1. Log in to the vSphere Client with a user account that has administrative privileges.
  2. Navigate to Administration > Roles.
  3. Select the VsmSvcRole and click on EDIT.
  4. In the pop-up window, navigate to Sessions > View and stop sessions.
  5. Click SAVE to apply the changes. Ensure the role’s privileges now include the ability to terminate sessions.

This adjustment does not require any service restarts, making it a straightforward fix that can be implemented immediately.

Long-Term Resolution

VMware has acknowledged the issue and is working on a resolution to be included in a future software update. More info VMware KB 94967

Minimum vSphere privileges to install or remove…

Minimum vSphere privileges to install or remove patch from ESXi

Minimum vSphere privileges to install or remove…

I recently got a question from our field inquiring about the minimum vSphere privileges that would be required to either install or remove a patch (VIB/Component) from an ESXi host. The customer was interested in using PowerCLI and specifically the ESXLI interface to automate the installation […]


VMware Social Media Advocacy

Dynamic ESXi firewall rulset for non-standard…

Dynamic ESXi firewall rulset for non-standard…

For most users who configure syslog for their ESXi hosts (hopefully everyone is doing that for audit, compliance and troubleshooting purposes), they typically stick with the default syslog ports 514 for UDP/TCP or 1415 for TLS. A huge benefit of using the default syslog ports is that the ESXi […]


VMware Social Media Advocacy

Inventory and Calculator scripts for VCF and…

Inventory and Calculator scripts for VCF and…

There are two new tools to help understand and calculate the required subscription capacity for the new VMware Cloud Foundation (VCF) and VMware vSphere Foundation (VVF) offerings, which are licensed based on physical CPU Cores for compute and total raw physical storage (TiBs) for vSAN.


VMware Social Media Advocacy