Replace Certificate task does not complete in the SDDC Manager UI
search cancel

Replace Certificate task does not complete in the SDDC Manager UI

book

Article ID: 414727

calendar_today

Updated On:

Products

VMware Cloud Foundation

Issue/Introduction

The progress of REPLACE_CERTIFICATE reached 100%, but never end

Environment

SDDC Manager 5.x

Resolution

Since this issue is cosmetic, it can be safely ignored after verifying that the certificate has been successfully updated.

Before ignoring the task, confirm that the new certificate is correctly applied.

Example:
If the certificate update was performed for NSX, log in to the NSX Manager UI and navigate to System > Certificates to verify that the new certificate is listed and active.

You can also use sos utility to verify if the update certification task has completed successfully. certificate-health shows the current expiry date of each component.: SoS Utility Options

  1. SSH into SDDC manager as the vcf user and su to the root user 
  2. Run the following command to verify certificates
    /opt/vmware/sddc-support/sos --certificate-health --domain-name ALL

If further action is required, note that the workaround involves manual database edits.
Please open a Broadcom Support request for assistance with performing these changes.

Additional Information

If a failed Replace Certificate task remains in the SDDC Manager UI, it may lead to related issues as described in the following article:
SDDC Manager Precheck error : Failed workflows: Certificate Operation: REPLACE_CERTIFICATE