Unable to replace SSL custom certificate for SDDC Manager
book
Article ID: 406723
calendar_today
Updated On:
Products
VMware SDDC Manager
Issue/Introduction
Message: "Failed to replace certificate for SDDC Manager" - "Remediation Message", " Reference Token" and "Cause" are blank.
Error in operationsmanager.log: "Certificate chain validity check against current PKIXParameters failed java.security.cert.CertPathValidatorException: CA key usage check failed: keyCertSign bit is not set"
Environment
VCF
Cause
The keyCertSign can only be asserted if the cert is a valid CA cert.
Resolution
The Certificate Authority cert is misconfigured- it will need to be created with the keyCertSign bit set correctly.