Error fetching certificate(s) in vCenter UI Certificate Manager after replacing certificate
search cancel

Error fetching certificate(s) in vCenter UI Certificate Manager after replacing certificate

book

Article ID: 401175

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

"Error occurred while fetching machine certificates" or "Error occurred while fetching vmca root cert" when you click on vCenter Certificate Manager.

 

Environment

VMware vCenter Server 7.0.x

VMware vCenter Server 8.0.x

Cause

Forward and reverse DNS records are required for vCenter to function properly.

vpxd.log:

YYYY:MM:DD:hh:mm:ss Z warning vpxd[12345] [Originator@2345 sub=vpxUtil opID=##########-##] getaddrinfo failed; host: <PNID OF ESXI HOST>, e: N7Vmacore15SystemExceptionE(Name or service not known)

Resolution

  • Verify DNS entries exist for the vCenter by running nslookup.

nslookup <vCenter_FQDN>

    • Verify the FQDN resolves to the vCenter.  

nslookup <vCenter_IP>

    • Verify the IP resolves to the vCenter.  

  • One of nslookup fails and indicates a missing record.
  • To resolve this issue, add the missing PTR (for missing IP) or A record (for missing FQDN) in DNS ensuring the records are properly configured in the DNS server.
  • Restart all services on vCenter.
  • Verify Certificate Manager no longer shows errors.