Unable to replace SSL custom certificate for SDDC Manager
search cancel

Unable to replace SSL custom certificate for SDDC Manager

book

Article ID: 406723

calendar_today

Updated On:

Products

VMware SDDC Manager

Issue/Introduction

  • Message: "Failed to replace certificate for SDDC Manager" - "Remediation Message", " Reference Token" and "Cause" are blank.
  • Error in operationsmanager.log: "Certificate chain validity check against current PKIXParameters failed java.security.cert.CertPathValidatorException: CA key usage check failed: keyCertSign bit is not set"

Environment

VCF 

Cause

The keyCertSign can only be asserted if the cert is a valid CA cert.

Resolution

The Certificate Authority cert is misconfigured- it will need to be created with the keyCertSign bit set correctly.