Error When Replacing AD over LDAPS Certificate: "Cannot configure identity source due to Certificate is not valid: NotAfter:"
search cancel

Error When Replacing AD over LDAPS Certificate: "Cannot configure identity source due to Certificate is not valid: NotAfter:"

book

Article ID: 427494

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

Environment

VMware vCenter Server

Cause

An expired certificate resides within the LDAPS certificate store. This will prevent the GUI from replacing the certificates when trying to import new ones: 

Resolution

Use the vCert tool to check and remove the

  1. To check certificates use "1. Check current certificate status". 
  2. If an expired LDAPS certificate appears, follow these steps to get into your LDAPS certificate store and remove the expired cert(s).
    • 3. Manage certificates
    • 11. LDAPS Identity Source certificates
    • 2. Remove Certificate