Symptoms:
- You are using VMCA as an intermediate/subordinate certification
- You have verified all certificates across the environment are correct and consistent
When starting the vmware-vsan-health service on the vCenter, we see the following error messages in the vpxa.log on the hosts:
2020-01-28T00:27:38.423Z info vpxa[16742038] [Originator@6876 sub=Default opID=vsan-PC-59d27b8701b25-sq111:j1-W910-sq123:j2-c6-98] [VpxLRO] -- ERROR lro-52 -- vsanSystem -- vim.host.VsanSystem.fetchVsanSharedSecret: vim.fault.NotAuthenticated:
--> Result:
--> (vim.fault.NotAuthenticated) {
--> faultCause = (vmodl.MethodFault) null,
--> faultMessage = <unset>,
--> object = 'vim.host.VsanSystem:vsanSystem',
--> privilegeId = "none"
--> msg = "Received SOAP response fault from [<cs p:000000a694a672d0, TCP:localhost:8307>]: fetchVsanSharedSecret
--> The session is not authenticated."
--> }
--> Args:
-->
This eventually leads to the host disconnecting from vCenter with the following messages in the vpxa.log:
2020-01-27T23:58:24.985Z error vpxa[16721871] [Originator@6876 sub=HTTP session map] Out of HTTP sessions: Limited to 500
2020-01-27T23:58:34.991Z error vpxa[16721873] [Originator@6876 sub=HTTP session map] Out of HTTP sessions: Limited to 500
2020-01-27T23:58:44.993Z error vpxa[16721898] [Originator@6876 sub=HTTP session map] Out of HTTP sessions: Limited to 500
2020-01-27T23:58:54.995Z error vpxa[16721875] [Originator@6876 sub=HTTP session map] Out of HTTP sessions: Limited to 500
2020-01-27T23:59:04.990Z error vpxa[16721874] [Originator@6876 sub=HTTP session map] Out of HTTP sessions: Limited to 500
2020-01-27T23:59:14.998Z error vpxa[16721871] [Originator@6876 sub=HTTP session map] Out of HTTP sessions: Limited to 500
2020-01-27T23:59:25.002Z error vpxa[16721899] [Originator@6876 sub=HTTP session map] Out of HTTP sessions: Limited to 500
2020-01-27T23:59:35.006Z error vpxa[16721870] [Originator@6876 sub=HTTP session map] Out of HTTP sessions: Limited to 500