After updating the leaf cert for VMware Harbor Registry control plane x509: certificate signed by unknown authority"while applying changes to VMware Harbor Registry Tile
search cancel

After updating the leaf cert for VMware Harbor Registry control plane x509: certificate signed by unknown authority"while applying changes to VMware Harbor Registry Tile

book

Article ID: 400126

calendar_today

Updated On:

Products

VMware Tanzu Platform

Issue/Introduction

 After updating the leaf cert for VMware Harbor Registry control plane x509: certificate signed by unknown authority"while applying changes to VMware Harbor Registry Tile

The task output shows the following errors.

Updating deployment:
  Expected task '82985' to succeed but state is 'error'
Task 82985 | 17:51:15 | L starting jobs: harbor-app/xxxxxxxxxx (0) (canary) (00:06:41)
                    L Error: 'harbor-app/xxxxxxxxxx (0)' is not running after update. Review logs for failed jobs: harbor, harbor-enable-bosh-dns, system-metrics-agent
Task 82985 | 17:56:16 | Error: 'harbor-app/xxxxxxxxxx(0)' is not running after update. Review logs for failed jobs: harbor, harbor-enable-bosh-dns, system-metrics-agent

Task 82985 error
Exit code 1



In the Harbor container registry logs provided by the customer and in docker folder and in dockerd.stderr.log file, the following errors are seen

time="2025-05-29T22:22:19.919807844Z" level=error msg="Handler for POST /v1.41/auth returned error: Get \"https://xxxxxxxx.com/v2/\": x509: certificate signed by unknown authority"
time="2025-05-29T22:22:24.983641958Z" level=info msg="Error logging in to endpoint, trying next endpoint" error="Get \"https://xxxxxxxxcom/v2/\": x509: certificate signed by unknown authority"

Resolution

Certificate Authority has changed, In the cert chain intermediate certificate is missing, added intermediate certificate to the Harbor tile under the CA certificate and customer did apply changes and that resolved the issue.