After making some changes in domain (added some users) automatical synchronization settings in domain doesn't synchronized correctly.
There is a known issue for this behaviour and we can fix this with Postman and REST API. To set LDAP Synchronization options via the Cloud Director API we should perform these steps:
Log into the Cloud Director API as a System Administrator:
Request:
POST https://vcloud-director-fqdn/cloudapi/1.0.0/sessions/provider
Headers:
Accept: application/json;version=34.0
Authorization: Basic (Encoded username@system / password)
You can use environments and tests in Postman for more convient way to store Token and vCD FQDN:
var bearer = postman.getResponseHeader("x-vmware-vcloud-access-token")
pm.environment.set("x-vmware-vcloud-access-token",bearer)
data:image/s3,"s3://crabby-images/4012c/4012c31c3d7a8e0879a8a4288e20ec485877ac1a" alt=""
data:image/s3,"s3://crabby-images/c6dd7/c6dd7453ff9658e2bbac56a4428e5825228b1d1f" alt=""
data:image/s3,"s3://crabby-images/9c74c/9c74c0aa0eb9ae8c1eb10a9aaed98e9a9cd3d643" alt=""
data:image/s3,"s3://crabby-images/30dd6/30dd6640908716e72566d8e8435dfc49d1cadad2" alt=""
In next requests you can use Bearer token that contains variable {{X-VMWARE-VCLOUD-ACCESS-TOKEN}}
data:image/s3,"s3://crabby-images/27a21/27a21656ec6cd468cea68677dfaa4c11f40c5363" alt=""
We can get current LDAP synchronization settings using next request:
Request:
POST https://vcloud-director-fqdn/api/admin/extension/settings/general
Headers:
Accept: application/*+xml;version=34.0
Authorization: Bearer {{X-VMWARE-VCLOUD-ACCESS-TOKEN}}
Note in the response the values given for the LDAP synchronization settings, for example:
<vmext:SyncStartDate>2020-09-23T02:00:00.000Z</vmext:SyncStartDate>
<vmext:SyncIntervalInHours>24</vmext:SyncIntervalInHours>
Take the entire XML response from the above and change only these synchronization settings to the desired values, for example:
<vmext:SyncStartDate>2021-04-09T06:30:00.000Z</vmext:SyncStartDate>
<vmext:SyncIntervalInHours>12</vmext:SyncIntervalInHours>
WARNING! Do not change any other parts of the XML which pertain to other System settings!
Put back this entire XML which includes our changes:
Request:
PUT https://vcloud-director-fqdn/api/admin/extension/settings/general
Headers:
Accept: application/*+xml;version=34.0
Content-Type: application/vnd.vmware.admin.generalSettings+xml
Authorization: Bearer {{X-VMWARE-VCLOUD-ACCESS-TOKEN}}
Request Body:
Entire edited XML from GET in previous steps.
data:image/s3,"s3://crabby-images/b0f75/b0f75314b20358107eaf9d746bb3a8a2fe0a7684" alt=""
If everything goes well we will get 200 OK status
data:image/s3,"s3://crabby-images/bcf98/bcf98350f5033372e205f86ed20591af7020831d" alt=""
Verify in the VCD database if the times have changed for the task using the SQL query you mentioned:
select client_activity_name, last_execution_time, next_execution_time from scheduled_activity_jobs where client_activity_name like '%Ldap%';
data:image/s3,"s3://crabby-images/b89d0/b89d0c0855353eb34f293403af51bf34fb6b92fc" alt=""
data:image/s3,"s3://crabby-images/5375a/5375a2e807de755526d0cc9f81e93b1b1dbac1d5" alt=""
You can also get details of the Cell this Job should be running on using the following SQL query:
select activity.id,
activity.framework_token,
activity.entity_id,
activity.running_on,
scheduled_activity_jobs.client_activity_name,
cells.instance_id,
cells.name,
cells.primary_ip,
cells.is_active
from activity
left join scheduled_activity_jobs on scheduled_activity_jobs.job_handle = activity.state_handle
left join cells on activity.running_on like '%'||cells.instance_id
where scheduled_activity_jobs.client_activity_name like '%LdapSyncJob%'
order by activity.running_on;
data:image/s3,"s3://crabby-images/374e1/374e1c5f3e06bfca89447a9066cff3f4e72c1b5b" alt=""
The Cell Management Tool can also be used on Cells to verify if the Job is present:
root@vcdlab1197 [ ~ ]# /opt/vmware/vcloud-director/bin/cell-management-tool cell -i $(service vmware-vcd pid cell) -tt | grep LdapSyncJob
| c0011945-e9f6-3eb4-8ec4-357e3f2027ee | 2021-04-09 11:21:17.034 | 2021-04-09 23:21:17.033 | STATUS_QUEUED | LdapSyncJob |
root@vcdlab1197 [ ~ ]#
Comments?
Leave us your opinion.