Machine SSL certificate replacement with custom certificate fails
vCenter - /var/log/vmware/vmcad/certificate-manager.log will show errors similar to the following entries:
YYYY-MM-DDTHH:MM:SS ERROR certificate-manager Error while replacing Machine SSL Cert, please see /var/log/vmware/vmcad/certificate-manager.log for more information.
YYYY-MM-DDTHH:MM:SS ERROR certificate-manager {
"resolution": null,
"problemId": null,
"componentKey": null,
"detail": [
{
"id": "install.ciscommon.command.errinvoke",
"translatable": "An error occurred while invoking external command : '%(0)s'",
"localized": "An error occurred while invoking external command : ''",
"args":
"Error in creating a new entry for __MACHINE_CERT in VECS Store MACHINE_SSL_CERT."
]This issue primarily occurs if there is a mismatch in the certificate and the private key used during certificate replacement.
Verify the MD5 check against the private key and the certificate files as both should match if the private key belongs to the same certificate.
openssl x509 -in <path to the Certificate file> -noout -modulus | openssl md5
openssl rsa -in <path to the Private Key file> -noout -modulus | openssl md5openssl rsa -in <path to the Private Key file> -noout -modulus | openssl md5 -non-fips-allow Example: [ ~/certs ]# openssl x509 -in ./FullChain.cer -noout -modulus | openssl md5
(stdin)= 55d84795791549fe72fc498c69f0dd2d
[ ~/certs ]# openssl rsa -in ./vmca_issued_key.key -noout -modulus | openssl md5
(stdin)= 6b84b1c62e91dbfc6b9f9efa5d34fb86Both output strings needs to match, otherwise the key and certificate are not a pair. Administrator will need to correct the private key file during the certificate replacement or regenerate the certificate by creating new certificate signing request (CSR) and private key. For more information, refer to Machine SSL certificate renewal using Custom Certificate Authority (CA) in vCenter Server.
Note: Should the issue reoccur despite the output strings matching, contact support by opening a support case.