Knowledge Base
The VMware Knowledge Base provides support solutions, error messages and troubleshooting guides

|
Logging in to vSphere Client 5.1 fails with the error: The server took too long to respond (2038918)
Symptoms
- After upgrading to vCenter Server 5.1, you are unable to log in to the vSphere Client or the vSphere Web Client, you see the error:
The command has timed out as the remote server is taking too long to respond
- Operations time out and vCenter Server tasks appear to be slow.
- Identity source is set to a large domain with many Organizational Units (OUs) and users.
- If you change the Base DN to a smaller OU in the AD identity source configuration of SSO after logging into Web Client as the SSO Administrator, you are able to log in.
Cause
This issue may occur if:
- SSPI calls take a long time for the SSO server to complete.
- SSO server completes the results, but the client times out before it receives results from SSO.
- Base DN for users/groups is set to the root of the domain.
- When you log in from vSphere Client using Windows session authentication, some calls in SSO take unusually long time due to which vSphere Client times out with the error The command has timed out as the remote server is taking too long to respond. This impacts other logins from vSphere Client or Web Client intermittently.
- If you check AD identity source configuration in SSO after logging into webClient as SSO administrator, Base DN is set to the root of the domain without using AD's Global Catalog Server URL.
Resolution
To resolve this issue, update the Identity source for the SSO Active Directory object to utilize the Global Catalog Server URL.
To update the Identity source for the SSO Active Directory object to utilize the Global Catalog Server URL:
- Log in to SSO via the vSphere Web Client as the admin@system-domain user.
- Navigate to Administration > Sign-On and Discovery > Configuration > Edit the Identity source for the Domain.
- Modify the Primary Server URL:
- Global Catalog address
For example:
ldap://global_server:3268
- Secure Global Catalog address
For example:
ldaps://global_server:3269 - Secure Global Catalog address
- You may be required to enter the password if the authentication type is set to Password.
- Click OK.
Related Education
For more information, see the Microsoft Technet article What Is the Global Catalog?
Note: The preceding link was correct as of December 3, 2012. If you find the link is broken, provide feedback and a VMware employee will update the link.
See Also
Request a Product Feature
To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.
Actions
KB:
- Updated:
- Categories:
- Languages:
- Product Family:
- Product(s):
- Product Version(s):

