[<YYYY-MM-DD>T<TIME>] [INFO ] aggregator-query-service-152 70000066 100004 200001 com.vmware.vise.search.transport.impl.AggregatorQueryServiceImpl QueryService LinkedQueryService(https://<vCenterFQDN>:443/invsvc) failed to respond: com.vmware.vise.search.transport.HostConnectException: Unable to connect to VMware Inventory Service -(https://<vCenterFQDN>:443/invsvc).
com.vmware.vise.search.transport.HostConnectException: Unable to connect to VMware Inventory Service - (https://vcenterfqdn:443/invsvc)
at com.vmware.vise.util.concurrent.ExecutorUtil$2.run(ExecutorUtil.java:195)
at com.vmware.vise.util.concurrent.ExecutorUtil$ThreadContextPropagatingRunnable.run(ExecutorUtil.java:928)
at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1152)
at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:622)
at java.lang.Thread.run(Thread.java:745)
Caused by: com.vmware.vim.vmomi.client.exception.SslException: com.vmware.vim.vmomi.core.exception.CertificateValidationException: Server certificate chain not verified
at com.vmware.vim.vmomi.client.common.impl.ResponseImpl.setError(ResponseImpl.java:251)Review the certificates in the VMware Endpoint Certificate Store (VECS) to verify that the signing certificates of the other ELM vCenter Server nodes are present. If any are missing, import the missing information.
/usr/lib/vmware-vmafd/bin/vecs-cli entry list --store TRUSTED_ROOTS --text | grep -E "Subject:|Issuer:|Not Before:|Not After|Alias"
Example Output
Alias : 9e#######c89d0c5c7d0aa####52c19e7913
Issuer: CN=<FDQN of vCenterA>, DC=vsphere, DC=local, C=US, ST=California, O=<FDQN of vCenterA>, OU=VMware Engineering
Not Before: <MM DD hh:mm:ss YYYY> GMT
Not After : <MM DD hh:mm:ss YYYY> GMT
Subject: CN=<FDQN of VCSA2>, DC=vsphere, DC=local, C=US, ST=California, O=<FDQN of vCenterA>, OU=VMware Engineering
Alias : 5######8ffdd3d508652855b9######0e0c51d19
Issuer: CN=<FDQN of vCenterB>, DC=vsphere, DC=local, C=US, ST=California, O=<FDQN of vCenterB>, OU=VMware Engineering
Not Before: <MM DD hh:mm:ss YYYY> GMT
Not After : <MM DD hh:mm:ss YYYY> GMT
Subject: CN=<FDQN of VCSA1>, DC=vsphere, DC=local, C=US, ST=California, O=<FDQN of vCenterB>, OU=VMware Engineering
/usr/lib/vmware-vmafd/bin/dir-cli trustedcert publish --cert <PATH_TO_CERTIFICATE> --login <VSPHERE_ADMINISTRATOR>
Example/usr/lib/vmware-vmafd/bin/dir-cli trustedcert publish --cert /tmp/certs/vCenterA_root.crt --login [email protected]
/usr/lib/vmware-vmafd/bin/vecs-cli force-refreshFor more information on dir-cli and vecs-cli, see dir-cli Command Reference and vecs-cli Command Reference.
"Could not connect to one or more vCenter Server Systems: https://vCenterFQDN: 443/sdk" error in the vSphere Web Client