YYYY-MM-DDTHH:MM:SSZ INFO certificate-manager please see service-control.log for service statusService-control failed. Error Failed to start vmon services.vmon-cli RC=1, stderr=Failed to start updatemgr services. Error: Operation timed outYYYY-MM-DDTHH:MM:SSZ error vmware-vum-server[7F3EAB8FE700] [Originator@6876 sub=Default] [rpcConnectionWrapper,214] SSL cert. verification failed for host http://FQDN.OF.VCENTER.SERVER:80/. Vmacore::Ssl::SSLException: SSL Exception: Verification parameters:--> PeerThumbprint: XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX:XX--> ExpectedThumbprint: YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY--> ExpectedPeerName: FQDN.OF.VCENTER.SERVER--> The remote host certificate has these problems:-->--> * unable to get local issuer certificateVMware vCenter Server 6.5
This issue is resolved in vCenter Server 6.5 Update 2.
- Log in to vCenter Server Appliance as root.
- Change the file permission of /etc/vmware/.buildInfo from 640 back to 444:
chmod 444 /etc/vmware/.buildInfo
- Replace the Machine SSL certificate.
- Take a backup of SSO domain (PSC(s), vCenter Server(s), etc.).
- Disable the VMware Update Manager Service.
- Log in to the vCenter Server using the vSphere Web Client.
- On the vSphere Web Client Home page, click System Configuration.
- Under System Configuration, click Services.
- From the Services list, right-click the VMware vSphere Update Manager service.
- Navigate to Start up Policy > Disabled.
- Re-try to replace the SSL certificates.
For more information, see Configuring the vSphere 6.0 U1b or later VMware Certificate Authority as a Subordinate Certificate Authority.
- Re-enable the VMware Update Manager Service.
- Log in to the vCenter Server using the vSphere Web Client.
- On the vSphere Web Client Home page, click System Configuration.
- Under System Configuration, click Services.
- From the Services list, right-click the VMware vSphere Update Manager service.
- Navigate to Start up Policy > Automatic
- Connect to the vCenter Server using SSH and run the following commands:
/usr/lib/vmware-updatemgr/bin/updatemgr-util refresh-certs/usr/lib/vmware-updatemgr/bin/updatemgr-util register-vcservice-control --start vmware-updatemgr Verify that VMware Update Manager is accessible in the vSphere Web Client.