SSO ChecksA single certificate has a trust mismatch. This requires an execution of lsdoctor.py with the –trustfix flag on this vCenter server node. • [FAIL] <vcenter-server-FQDN> (VC Server or CGW) [FAIL] SSL Trust Mismatch Please run python lsdoctor.py --trustfix option on this node (or a vCenter in this SSO site). Services grouped by SSL Trust: ##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##: - sso:groupcheck - sso:admin - sso:sts
...
vCenter
SSL Trust or Anchor Mismatches typically result from expired certificates, broken trust chains, or unsuccessful certificate replacements.
To resolve the issue:
lsdoctor to the vCenter filesystempython lsdoctor.py -t”Follow up actions needed:
The lsdoctor tool can be downloaded here: Using the 'lsdoctor' Tool
https://knowledge.broadcom.com/external/article/344917/using-the-vcf-diagnostic-tool-for-vspher.html