Error while replacing Machine SSL Cert with error "Valid PEM but no BEGIN CERTIFICATE/END CERTIFICATE delimiters"
search cancel

Error while replacing Machine SSL Cert with error "Valid PEM but no BEGIN CERTIFICATE/END CERTIFICATE delimiters"

book

Article ID: 409823

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

Machine SSL Certificate replacement fails with below error messages

Error while replacing Machine SSL Cert, please see /var/log/vmware/vmcad/certificate-manager.log for more information

/var/log/vmware/vmcad/certificate-manager.log:

####-##-##T##:##:##.335Z INFO certificate-manager  Certificate backup created successfully
####-##-##T##:##:##.337Z ERROR certificate-manager  Exception caught for provided certificate - /tmp/filename.cer. Valid PEM but no BEGIN CERTIFICATE/END CERTIFICATE delimiters. Are you sure this is a certificate?. Only SHA-2 RSA algorithms are supported on the vCenter Server.
####-##-##T##:##:##.338Z ERROR certificate-manager  Error while replacing Machine SSL Cert, please see /var/log/vmware/vmcad/certificate-manager.log for more information.
####-##-##T##:##:##.338Z ERROR certificate-manager  Exception caught for provided certificate - /tmp/filename.cer. Valid PEM but no BEGIN CERTIFICATE/END CERTIFICATE delimiters. Are you sure this is a certificate?. Only SHA-2 RSA algorithms are supported on the vCenter Server.
####-##-##T##:##:##.338Z INFO certificate-manager  Performing rollback of Machine SSL Cert...

 

Cause

This issue is caused due to invalid characters in the supplied certificates or the format is invalid

The machine_name_ssl.cer should be a complete chain file similar to the order below:

-----BEGIN CERTIFICATE-----

<alphanumeric certificate characters> <----- Certificate

-----END CERTIFICATE-----

-----BEGIN CERTIFICATE-----

<alphanumeric certificate characters> <----- Intermediate Certificate

-----END CERTIFICATE-----

-----BEGIN CERTIFICATE-----

<alphanumeric certificate characters> <----- Root Certificate

-----END CERTIFICATE-----

Resolution