Knowledge Base
The VMware Knowledge Base provides support solutions, error messages and troubleshooting guides

|
Logging in to vCenter Orchestrator using SSO fails with the error: Failed trying to retrieve token: ns0:RequestFailed: Delegate is invalid (2039229)
Symptoms
- Cannot login to vCenter Orchestrator using vCenter Single Sign On (SSO)
- Logging in to vCenter Orchestrator using SSO fails
- You see the error:
Failed trying to retrieve token: ns0:RequestFailed: Delegate is invalid
- When configured using LDAP, you are able to log in to vCenter Orchestrator and you see the message:
After verifying that the user attempting to login is in the admin group in vCenter and that SSL certs have been verified. Test login's via the vCO configuration page are successful.
Cause
Resolution
To resolve this issue, add
System-Domain to the list of Default Domains in the SSO configuration.To add
System-Domain to the list of Default Domains in the SSO configuration:- Log in to the vSphere Web Client.
- In the vSphere Web Client home page, click Administration.
- In the left pane, under Sign-On and Discovery, click Configuration.
- From the list of domains, select System-Domain and click Add to Default Domains.
- In the Default Domains pane, click Save.
Note: You should wait for about a minute for the SSO configuration to be applied.
Request a Product Feature
To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.
Actions
KB:
- Updated:
- Categories:
- Languages:
- Product Family:
- Product(s):
- Product Version(s):

