Notification Emails triggered regarding Expired Migrated Certificate on VMware Cloud Director
search cancel

Notification Emails triggered regarding Expired Migrated Certificate on VMware Cloud Director

book

Article ID: 407862

calendar_today

Updated On:

Products

VMware Cloud Director

Issue/Introduction

  • System administrators receive email notifications stating that the migrated certificate for a VMware Cloud Director (VCD) cell has expired.
    Your certificate library item Migrated certificate - YYYY-MM-DDTHH:MM:SS.#### - cellFQDN (id: ############, description: Migrated during cell startup at: YYYY-MM-DDTHH:MM:SS.#### , org: System) expired 60 day(s) ago at YYYY-MM-DDTHH:MM:SS.#### [Etc/UTC].

Environment

VMware Cloud Director 10.x

Cause

This issue occurs because the VCD cell is still using an expired certificate. The VCD system's health monitoring detects the expiration and automatically sends alert emails to the administrators.

Resolution

Prerequisites:

Ensure you have a new, valid certificate already imported into the Certificate Library.

Critical: Take a snapshot of the vCD cells before making any manual changes to the endpoint configurations.

Step 1: Identify Expired Certificates and Usage

Before deleting a certificate, you must verify if it is still actively "consumed" by any system components.

  1. Navigate to Administration > Certificates Library.
  2. Locate the expired certificate in the list.
  3. Check the Consumers column:
    • If Consumers = 0: The certificate is not in use and can be safely deleted (Step 3).
    • If Consumers ≥ 1: The certificate is still attached to one or more vCD cells. You must update those cells first.

Step 2: Update Cell Endpoint Configurations

If the expired certificate is still in use, follow these steps to switch to the new certificate:

  1. Navigate to Resources > Cloud Cells.
  2. Select a cell from the list.
  3. Click on the Endpoints Configuration tab.
  4. Review the certificates assigned to the Webserver and JMX endpoints.
  5. If an endpoint is still using the expired certificate:
    • Click Edit.
    • Select the new, valid certificate from the library.
    • Save the changes.

Repeat these steps for every cell listed in the environment until all endpoints are updated.

Step 3: Remove the Expired Certificate

Once all cells have been updated and the consumer count has dropped to zero, you can clean up the library.

  1. Return to Administration > Certificates Library.
  2. Verify the Consumers count for the expired certificate now shows 0.
  3. Select the expired certificate and click Delete.

If the cells are using the self signed certificates, refer to the Generating Self-Signed Certificates for the VMware Cloud Director HTTPS Endpoint documentation.
If the CA certificates are already available, refer: Change the Certificates of a Cell

Additional Information