vSAN File Service enablement fails at 20% with the below error:
The operation is not allowed in the current state. Cannot create domain for the vSAN file service: Failed to check domain configuration: (vmodl.fault.SystemError) { msg = "Received SOAP response fault from [<<io_obj p:0x00007feb3c5ae668, h:138, <UNIX ''>, <UNIX '/var/run/envoy-hgw/hgw-pipe'>>, /hgw/host-3460472/vsan>]: performDomainConfigAdvancedCheck\nVDFS datastore is not present", reason = "VsanInvalidState('VDFS datastore is not present')" }.
From the vdfsd-proxy.log for all hosts in the cluster the following is seen:
2025-07-29T16:10:28.723Z|f-0-000000009|DISCO: No(29) vdfsd-proxy[99527885] 66857170-1f05-0551-1099-############ reachable at >172.##.##.101 -- esxi1.example<---orchestrator host chosen by vSAN during vSAN File Service deployment2025-07-29T16:10:28.724Z|f-0-000000009|PROXY: No(29) vdfsd-proxy[99527885] 48a46d68-5aca-c81b-a747-############ conn-0: Remote >server connection with 172.##.##.101:1564 fd=612025-07-29T16:10:28.724Z|f-0-000000009|PROXY: No(29) vdfsd-proxy[99527885] 48a46d68-5aca-c81b-a747-############ conn-0: clt: >127.0.0.1 fd=58 -- svr: 172.##.##.101 fd=612025-07-29T16:10:28.730Z|m-0----------|VDFSSKT: Er(27) vdfsd-proxy[99527885] handshakeVer: failed to locate peer's certificate >thumbprint2025-07-29T16:10:28.730Z|m-0----------|VDFSSKT: No(29) vdfsd-proxy[99527885] readErr: fd=61 -- AsyncSocketException: socket closing >after error (peer=172.##.##.101:1564, local=172.##.##.106:33169), type = Internal error -- Failure2025-07-29T16:10:28.730Z|f-0-000000009|VDFSSKT: Er(27) vdfsd-proxy[99527885] TLSConnect: sslConn failed: Failure (195887105)2025-07-29T16:10:28.730Z|f-0-000000009|PROXY: Er(27) vdfsd-proxy[99527885] 48a46d68-5aca-c81b-a747-############ conn-0: TLS >handshake with server 172.##.##.101 failed: Failure2025-07-29T16:10:28.730Z|f-0-000000009|PROXY: Er(27) vdfsd-proxy[99527885] 48a46d68-5aca-c81b-a747-############ conn-0: client: >127.0.0.1 fd=58 server: 172.##.##.101 fd=61 -- state: 1 FAILED: Failure2025-07-29T16:10:28.730Z|f-0-000000009|PROXY: No(29) vdfsd-proxy[99527885] 48a46d68-5aca-c81b-a747-############ conn-0: >172.##.##.101 fd=61: closing conn2025-07-29T16:10:28.730Z|f-0-000000009|VDFSSKT: No(29) vdfsd-proxy[99527885] fd=61 (mgr=0) -- closing2025-07-29T16:10:28.730Z|f-0-000000009|PROXY: No(29) vdfsd-proxy[99527885] 48a46d68-5aca-c81b-a747-############ conn-0: attempt 21: >failed: Failure, retrying
Note: The preceding log excerpts are only examples. Date, time, and environmental variables may vary depending on your environment.
VMware vSAN (All Versions)
vSAN File Services
vSAN File services deployment fails due to the host selected to be the orchestrator host for the deployment has a bad host cert resulting in the rest of the hosts in the cluster not trusting the thumbprint so the handshake fails.