Configure Microsoft CA certificate under VCF Instances in VCF Fleet Manager fails with error "Certificate authorities update failed."
search cancel

Configure Microsoft CA certificate under VCF Instances in VCF Fleet Manager fails with error "Certificate authorities update failed."

book

Article ID: 416470

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

  • Configuring the CA under VCF Management in VCF Operations Fleet Manager and selecting Microsoft CA  is successful 
  • Configuring the CA under VCF Instances in VCF Operations Fleet Manager and selecting Microsoft CA fails with the error "Certificate authorities update failed."
  • Configuring Microsoft CA certificate and generating the certificate using the configured Microsoft CA from SDDC Manager UI is successful;
  • Reproducing the issue while capturing a HAR file shows the following error in the Response you can use the following KB as a guide to obtain HAR capture How to collect a HAR log file for troubleshooting Cloud Director issues :
    {
        "type": "Error",
        "message": "Invalid input format.",
        "moreInformation": [
            {
                "name": "errorMessage",
                "value": "400 : \"{\"errorCode\":\"REST_INVALID_API_INPUT\",\"arguments\":[],\"message\":\"Invalid input\",\"remediationMessage\":\"Enter correct API input\",\"nestedErrors\":[
    
    {\"errorCode\":\"ANNOTATIONS_MISMATCH\",\"arguments\":[\"JSON parse error: Unrecognized character escape 's' (code 115)\"],\"message\":\"Following conditions do not match - JSON parse error: Unrecognized character escape 's' (code 115)\"}
    ],\"referenceToken\":\"######\"}\""
            }
        ],
        "httpStatusCode": 400,
        "apiErrorCode": 400
    }

Environment

  • VCF Operations 9.x

Cause

The issue occurs as a result of entering the User Name in the format of DOMAIN\username when configuring the Certificate Authority under VCF Instances in VCF Operations Fleet Manager UI. 

Resolution

Configure Microsoft CA certificate under VCF Instances in VCF Fleet using the steps below:
  1. Sign in to the VCF Operations UI (https://<VCF_Ops_FQDN>/ui) as local user admin.
  2. Navigate to Fleet Management → Certificates → VCF Instances  → CONFIGURE CA.
  3. Select Microsoft CA for Certificate Authority Type → Enter in CA Server URL  → Enter in User Name in UPN format  → Enter in the Password associated with the user  → Enter in the template name.

Additional Information

References: