After upgrading VMware Cloud Director to 10.3 or beyond, the virtual machine consoles are showing disconnected when accessing the UI via Load Balancer.
Environment
VMware Cloud Director 10.3
Cause
In VMware Cloud Director 10.3, we are no longer using the java keystore for certificate management. When you upgraded from 9.7 to 10.3, the certificates were updated to self signed certificates.
The default certificates only include the cell's hostname. When accessing the VMware Cloud Director UI through a load balancer, the traffic is routed to an individual cell, and the certificate is checked against the load balancers hostname. Since the load balancer hostname isn’t included in the default certificate, validation fails, preventing console proxy connections.
Resolution
Create and Import CA-Signed SSL Certificates for Your VMware Cloud Director Appliance.
Install wildcard certificates that include the hostname of every cell and the load balancer hostname.