"Failed to check VMware STS. The SSL certificate of STS service cannot be verified" while upgrading VCSA from 6.5 to 6.7/7.0
book
Article ID: 345432
calendar_today
Updated On:
Products
VMware vCenter Server
Issue/Introduction
Symptoms:
VCSA upgrade failed with vmidentity first boot
Error: Failed to check VMware STS.
com.vmware.vim.sso.client.exception.CertificateValidationException: The SSL certificate of STS service cannot be verified
Environment
VMware vCenter Server 7.0.x VMware vCenter Server Appliance 6.7.x VMware vCenter Server 6.7.x VMware vCenter Server Appliance 6.0.x VMware vCenter Server 6.0.x VMware vCenter Server Appliance 6.5.x VMware vCenter Server 6.5.x
Cause
If the vCenter was upgraded from 5.5, it retains lookup service certificate in STS_INTERNAL_SSL_CERT store which will be used by this url https://FQDN:7444/lookupservice/sdk
Resolution
To resolve the issue replace the certificate for STS_INTERNAL_SSL_CERT store.
Follow the below steps to replace the Certificate for STS_INTERNAL_SSL_CERT store:
Take a backup of both STS_INTERNAL_SSL_CERT and MACHINE_SSL_CERT store