[FAIL] Certificate Trust Check (UNTRUSTED|SIGNED-INTERMEDIATE)
Missing signing CA in TRUSTED_ROOTS!
Missing Subject:
<Certificate Subject>
Missing Authority Key:
<Authority Key of the Certificate>
vCenter Server 7.0.x
vCenter Server 8.0.x
vdt.log
YYYY-MM-DDTHH:MM:SSUTC
INFO VC VECS Check getCaTrustList: Getting CA trust list
YYYY-MM-DDTHH:MM:SSUTC DEBUG VC Certificate Authority Check __init__: {'Thumbprint': '##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##', 'Version': 2, 'SignatureAlg': 'sha512WithRSAEncryption', 'Issuer': '<Certificate Issuer Subject>', 'Valid From': 'YYYY-MM-DD HH:MM:SS GMT', 'Valid Until': 'YYYY-MM-DD HH:MM:SS GMT', 'Subject': '<Certificate Subject>', 'subjectKeyIdentifier': '##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##', 'authorityKeyIdentifier': 'keyid:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##\n', 'keyUsage': 'Digital Signature, Certificate Sign, CRL Sign', 'extendedKeyUsage': 'Code Signing'}
YYYY-MM-DDTHH:MM:SSUTC DEBUG VC Certificate Authority Check __init__: Checking certificate: <Certificate Subject> for problems
Add the missing Root CA certificate to vCenter Server by following the steps in Add a Trusted Root Certificate to the Certificate Store.
For example
If the missing CA Subject is "Entrust Code Signing Root Certification Authority – CSBR1":