/var/log/vmware/vcf/commonsvcs/vcf-commonsvcs.logYYYY-MM-DDTHH:MM:SS ERROR [common,#################] [c.v.v.i.sync.utils.VcSyncManagerUtil,cs-exec-#] Error connecting to vCenter vcenter-#, with exception {} com.vmware.vim.vmomi.client.exception.SslException: javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target at com.vmware.vim.vmomi.client.common.impl.ResponseImpl.setError(ResponseImpl.java:###) at com.vmware.vim.vmomi.client.http.impl.HttpExchange.run(HttpExchange.java:51)/var/log/vmware/vcf/operationsmanager/operationsmanager.logYYYY-MM-DDTHH:MM:SS. +0000 ERROR [vcf_om,#################] [c.v.e.s.c.s.l.LicenseServiceFactory,om-exec-##] Failed to instantiate License Service with endpoint VC_FQDNcom.vmware.evo.sddc.common.services.psc.exception.PscException: Unable to obtain Security Token Service from SSO 'VC_FQDN'{"message":"500 - \"{\\\"errorCode\\\":\\\"IDENTITY_INTERNAL_SERVER_ERROR\\\",\\\"arguments\\\":[],\\\"message\\\":\\\"Identity Internal Server Error\\\",\\\"referenceToken\\\":\\\"ABC###\\\"}\""} 'Internal Server Error'./var/log/vmware/vcf/commonsvcs/vcf-commonsvcs.log is as below:Caused by: java. security.cert. CertPathBuilderException: No issuer certificate for certificate in certification path found.Renew VAPI session - failed to obtain new sessionorg. springframework.web. client. ResourceAccessException: I/0 error on POST request for "https://VC_FQDN/rest/com/vmware/cis/session": certificate_unknown (##)at org. springframework.web. client. RestTemplate. createResourceAccessException (RestTemplate. java : ###)at org. springframework.web. client. RestTemplate. doExecute (RestTemplate. java : ###)Description: Generate NSX Input for configuring NSXProgress Messages: Failed to fetch object name(s) from vCenterCause: org.bouncycastle.tls.TlsFatalAlert: certificate_unknown(46) Unable to construct a valid chain No issuer certificate for certificate in certification path found.Note:
Scripted Process:
VcRootCaSync.py script to the SDDC Manager using Winscp or other file transfer protocol.python VcRootCaSync.py
Expected Output:/home/vcf ]# python VcRootCaSync.pyPlease provide SSO administrator user[[email protected]]:Provide password for [email protected]:Available vCenter Servers:[1] ACTIVE | vcsa1.example.com[2] ACTIVE | vcsa2.example.com
Select a vCenter server by entering the corresponding number: 1 Selected vCenter: vcsa1.example.com
Session token created successfully Root certificate saved to /tmp/root.cer
vCenter vcsa1.example.com Root Certificate Found:-----BEGIN CERTIFICATE-----##################################################################
-----END CERTIFICATE-----
Using randomly generated Alias: abc-def-vcsa1_RootCrt_EA0G
vCenter Root certificate added to SDDC Manager trust stores. Refreshing certificate store Deleting root certificate from temp
Manual Process:
/usr/lib/vmware-vmca/bin/certool --getrootca --cert=/tmp/root.cer/usr/lib/vmware-vmafd/bin/vecs-cli entry list --store trusted_rootsvi /tmp/root.cer to create an empty file with vi.
Press i to enter insert mode.
Paste the body of the certificate into the root.cer file.
Press esc to exit insert mode.
Type wq! and hit enter to write changes to the file and exit the vi editor.
pass=$(cat /etc/vmware/vcf/commonsvcs/trusted_certificates.key) trusted_certificates_store with the keytool.keytool -importcert -alias <aliasname> -file <certificate file> -keystore /etc/vmware/vcf/commonsvcs/trusted_certificates.store -storepass <trust store key>keytool -importcert -alias new_mgmt_root -file /tmp/root.cer -keystore /etc/vmware/vcf/commonsvcs/trusted_certificates.store -storepass $passkeytool -importcert -alias <aliasname> -file <certificate file> -keystore /etc/alternatives/jre/lib/security/cacerts --storepass changeitkeytool -importcert -alias new_mgmt_root -file /tmp/root.cer -keystore /etc/alternatives/jre/lib/security/cacerts --storepass changeit
Note: While the alias name can be arbitrary, it is recommended to use the alias name present in the vCenter's trusted root store for consistency.keytool -list -v -keystore /etc/vmware/vcf/commonsvcs/trusted_certificates.store -storepass $pass | lesscurl -X POST localhost/appliancemanager/trustedCertificates/refresh
Workaround:
If the SDDC UI is accessible, the root certificate can also be imported from the API Explorer.
awk 'NF {sub(//, ""); printf "%s\\n",$0;}' /tmp/vmca.crtFor example:root@vcenter-1 [ ~ ]# awk 'NF {sub(//, ""); printf "%s\\n",$0;}' /tmp/vmca.crt-----BEGIN CERTIFICATE-----<certicate..............>-----END CERTIFICATE-----\n
certificate and certificateUsageType.API Explorer > APIs for managing Trusted Certificates > POSTPEM format in the certificate field.TRUSTED_FOR_OUTBOUND into the certificateUsageType field.Execute.