Avi Integration with vCloud Director stalls at certificate verification step
search cancel

Avi Integration with vCloud Director stalls at certificate verification step

book

Article ID: 404274

calendar_today

Updated On:

Products

VMware Avi Load Balancer

Issue/Introduction

When you add an Avi Load Balancer Controller to VMware vCloud Director, the integration process may stall and fail to proceed after you accept the Avi portal's SSL certificate.

Screenshot of the error:

Cause

This issue occurs when the Common Name (CN) on the Avi Controller's SSL certificate does not match its Fully Qualified Domain Name (FQDN). vCloud Director requires this match to validate the controller's identity.

By default, the Avi Controller uses a generic 'System-Default-Portal-Cert', which does not have the correct FQDN, causing the validation to fail silently.

Resolution

To fix this, you must create a new controller certificate that uses the controller's FQDN as its Common Name and then apply it.

1. Create the Controller Certificate

  • In the Avi UI, navigate to 'Templates > Security > SSL/TLS Certificates'.
  • Click Create and select Controller Certificate.
  • Enter a descriptive certificate name.
  • In the Common Name field, enter the exact FQDN of your Avi Controller.
  • Fill in the other relevant fields, set a desired expiration period, and click Save.

2. Apply the New Certificate

  • Navigate to Administration > Settings and click the edit icon to modify the system settings.
  • Find the SSL/TLS Certificate section.
  • Remove the default certificate and, from the dropdown menu, select the new certificate you just created.
  • Click Save.

After applying the new certificate, return to vCloud Director and retry adding the Avi Load Balancer. The process should now complete successfully.