vSphere DRS functionality was impacted due to unhealthy state vSphere Cluster Services caused by the unavailability of vSphere Cluster Service VMs" alert in vSphere client UI
search cancel

vSphere DRS functionality was impacted due to unhealthy state vSphere Cluster Services caused by the unavailability of vSphere Cluster Service VMs" alert in vSphere client UI

book

Article ID: 404287

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

Environment

  • VMware vCenter Server 7.0.x
  • VMware vCenter Server 8.0.x

Cause

The issue is caused due to missing Subject Alternative Name entry in the solution user certificates. This can be validated using the new improved certificate management tool  vCert - Scripted vCenter Expired Certificate Replacement for all certificate management/replacement workflow. This tool helps to replace certificates with VMCA signed as well as custom CA signed certificates. 

To confirm the mismatch, follow the below steps:

  1. Run the vCert script on your vCenter server.
  2. Acknowledge the snapshot and risks warning.
  3. Enter the administrator credentials.
  4. Select option 1 (Check current certificate status) from the menu.

The script will perform a check, the output for solution users will show as "NO SAN"

Resolution

Before proceeding with the steps below, take both a backup and a snapshot of the vCenter Server Appliance. If the vCenter is part of a Enhanced Linked Mode (ELM) replication setup, also take a backup or offline (powered off) snapshot of all replicating vCenter ELM nodes.

To resolve this issue,

Replace the solution users certificate using the new improved certificate management tool  vCert - Scripted vCenter Expired Certificate Replacement for all certificate management/replacement workflow. This tool helps to replace certificates with VMCA signed as well as custom CA signed certificates. 

  1. Run the vCert script on your vCenter server.
  2. Acknowledge the snapshot and risks warning.
  3. Enter the administrator credentials. Select option 3 to manage certificates.
  4. Select option 2 to replace solution user certificates.
  5. Re-start all the vCenter services using the below command
    1. service-control --stop --all && service-control --start --all