vCert displaying STS ConnectionStrings MISCONFIG
search cancel

vCert displaying STS ConnectionStrings MISCONFIG

book

Article ID: 418319

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

STS displays a misconfigured connection string error:

Checking STS Server Configuration
-----------------------------------------------------------------
Checking VECS store configuration                              OK
Checking STS ConnectionStrings                          MISCONFIG

Environment

VMware vCenter Server 8.0 U3

Cause

Incorrect / outdated STS connection strings can cause the erroneous certificate status indication.

Resolution

  1. Take proper snapshots of ALL vCenter server nodes in ELM
  2. To validate, the tool vCert can be used Main Menu → Option 5 → Option 2 updates and validates the STS connection strings: vCert - Scripted vCenter expired certificate replacement
  3. To address this error, in vCert 6.1.0 or above when asked to "Update STS ConnectionStrings value to ldap://localhost:389? [N]" enter "Y" to update the value
    • NOTE: Services should be restarted on all vCenter nodes, this can be done by using vCert Main Menu → Option 8 → Option 1 → Y or by running the following command
      • service-control --stop --all && service-control --start --all

Additional Information

For more information see: vCenter services vapi-endpoint and vpxd-svcs fail to start with "Unexpected status code: 404"