VCF Installer fails on stage "Generate and Install VMCA Certificate on SDDC Manager"
search cancel

VCF Installer fails on stage "Generate and Install VMCA Certificate on SDDC Manager"

book

Article ID: 419768

calendar_today

Updated On:

Products

VMware SDDC Manager VMware Cloud Foundation

Issue/Introduction

VCF Installer fails on stage "Generate and Install VMCA Certificate on SDDC Manager"

/var/log/vmware/vcf/domainmanager/domainmanager.log: 
2025-11-13T03:20:52.451+0000 ERROR [vcf_dm,69154e939207b0499ff306684b0191b2,4328] [c.v.e.s.s.InstallSddcManagerVmcaCertificateLocalAction,dm-exec-23]  API failure during install certificate Code: 500, error: {"errorCode":"CERT_REPLACEMENT_FAILED","arguments":[],"message":"Cannot replace existing certificate with the input cert. Validations did not pass.\nMake sure the input cert chain is valid. The structure must be:\n\server cert\followed by \ntermediate certs\ followed by \CA cert\nA self signed server cert\nAll certs in the chain must conform to X.509 standards.\nAlso make sure that the DNS name in both the CN field and the optional Subject Alternative Name extension, is a resolvable hostname","causes":[{"type":"com.vmware.evo.sddc.appliance.utilities.error.CertValidatorException","message":"Cannot replace existing certificate with the input cert. Validations did not pass.

Environment

VCF 9.x 

Cause

The date and time set on the VCF Installer / SDDC Manager appliance is not in sync with the vCenter appliance. 

Resolution

Ensure NTP is configured on the vCenter Appliance and SDDC Manager and both report the same time (within 45 seconds)

To workaround the issue, see Failed to install VMCA Certificate on SDDC Manager

Additional Information

If converting or importing a brownfield vSphere environment to VCF, see: