vCenter Integrated Certificate Reregistration Fails in VCF Operations for Networks 9.0
search cancel

vCenter Integrated Certificate Reregistration Fails in VCF Operations for Networks 9.0

book

Article ID: 427630

calendar_today

Updated On:

Products

VCF Operations for Networks

Issue/Introduction

In VMware Cloud Foundation (VCF) Operations for Networks (formerly vRealize Network Insight), the integrated method for reregistering or updating a vCenter Server certificate may fail after the certificate has been renewed. This typically occurs when a license sync disruption prevents the collector from successfully reconnecting to the vCenter data source.

  • Failure to reconnect vCenter after certificate renewal.
  • Error messages in platform logs: getQueryResultDocIds() threw an exception. com.vnera.query.common.QueryException: Feature not supported.
  • Error messages in collector logs: Failed to find a certificate with kid <ID> and Failed to handle certificate change for host <vcenter_ip>.
  • Authentication failures or account locking during session creation.

Environment

VCF Operations for Networks 9.0.x

Cause

From version 9.0 onwards, VCF Operations for Networks uses an auto-acceptance mechanism for licenses. When a vCenter license is updated or a certificate is changed, the system requires approximately five minutes to synchronize the metadata. If changes are attempted within this five-minute sync window, the license acceptance process for the earlier session is disrupted, leading to a failure in the integrated certificate update method.

Resolution

This issue is resolved in VCF Operations for Networks 9.1 and fixed in patch 9.0.3.

To resolve the issue in version 9.0.x, follow these steps:

  1. Prerequisites:
    Ensure you have administrative credentials for the VCF Operations for Networks UI.
    Verify the new vCenter certificate is valid and trusted by the environment.
  2. Remove the Data Source:
    Navigate to Settings > Data Sources.
    Locate the affected vCenter integration and select Delete or Remove.
  3. Wait for Synchronization:
    Wait at least 5 to 10 minutes to allow the background license and metadata sync to clear the previous state.
  4. Re-add the vCenter Data Source:
    Click Add Source and select vCenter.
    Enter the FQDN/IP address and credentials for <vcenter_fqdn>.
    Accept the new certificate when prompted.
    Verify that the status changes to Active and flows become available in the UI.

Additional Information

This issue is fixed in patch 9.0.3

This issue is resolved in 9.1 version.