During upgrade from vCenter 6.7 to vCenter 7.0, Stage 2 fails with certificate-related error messages. Users will see two error dialogues:
Error Error in appending hostname/ip [hostname] to Cert.
Resolution: This is an unrecoverable error, please retry install.
Error An error occurred while invoking external command: 'Command: ['/usr/lib/vmware-vmca/bin/certool', '--server=[hostname]', '--genCIScert', '--privkey=/etc/certs/hvc/hvc.priv', '--cert=/etc/certs/hvc/hvc.crt', '--Name=hvc', '--FQDN=[hostname]'] Resolution: This is an unrecoverable error, please retry install. If you encounter this error again, please search for these symptoms in the VMware Knowledge Base for any known issues and possible resolutions.
The installer cannot proceed past this point and must be rolled back.
The error occurs because, often with an external PSC, the DCAdmins group is not a member of the CAAdmins group in vSphere SSO. This prevents proper certificate generation during the upgrade process, resulting in the access denied errors seen in the certool command.
CAAdmins
groupDCAdmins
group as a member of CAAdmins