/var/log/vmware/vCert/vCert.log) contains the following entry: INFO Could not find read permission for user vsan-health in VECS store vpxd-extensionAnd shows "Permissions" for vpxd-extension VECS store
Log : /var/log/vmware/vCert/vCert.log
-->--> PERMISSIONS FOR STORE: [vpxd-extension]--> OWNER : root--> USER ACCESS--> vlcm read--> wcp read--> 1020 read--> deploy read--> infraprofile write--> updatemgr read--> vsphere-ui read--> vpxd read--> analytics read--> vsm read--> imagebuilder read--> content-library read--> eam read--> 1004 read--> sps write--> vstatsuser read2026-04-10T12:59:32 EDT -04:00 INFO Users with expected read permissions: vlcm wcp deploy updatemgr vsphere-ui vpxd vsm vsan-health imagebuilder content-library eam vstatsuser analytics2026-04-10T12:59:32 EDT -04:00 INFO Users with expected write permissions: infraprofile sps2026-04-10T12:59:32 EDT -04:00 INFO Found read permission for user vlcm in VECS store vpxd-extension2026-04-10T12:59:32 EDT -04:00 INFO Found read permission for user wcp in VECS store vpxd-extension2026-04-10T12:59:32 EDT -04:00 INFO Found read permission for user deploy in VECS store vpxd-extension2026-04-10T12:59:32 EDT -04:00 INFO Found read permission for user updatemgr in VECS store vpxd-extension2026-04-10T12:59:32 EDT -04:00 INFO Found read permission for user vsphere-ui in VECS store vpxd-extension2026-04-10T12:59:32 EDT -04:00 INFO Found read permission for user vpxd in VECS store vpxd-extension2026-04-10T12:59:32 EDT -04:00 INFO Found read permission for user vsm in VECS store vpxd-extension
2026-04-10T12:59:32 EDT -04:00 INFO Could not find read permission for user vsan-health in VECS store vpxd-extension
2026-04-10T12:59:32 EDT -04:00 INFO Found read permission for user imagebuilder in VECS store vpxd-extension2026-04-10T12:59:32 EDT -04:00 INFO Found read permission for user content-library in VECS store vpxd-extension2026-04-10T12:59:32 EDT -04:00 INFO Found read permission for user eam in VECS store vpxd-extension2026-04-10T12:59:32 EDT -04:00 INFO Found read permission for user vstatsuser in VECS store vpxd-extension2026-04-10T12:59:32 EDT -04:00 INFO Found read permission for user analytics in VECS store vpxd-extension2026-04-10T12:59:32 EDT -04:00 INFO Found write permission for user infraprofile in VECS store vpxd-extension2026-04-10T12:59:33 EDT -04:00 INFO Found write permission for user sps in VECS store vpxd-extension2026-04-10T12:59:33 EDT -04:00 INFO Task Status: PERMISSIONS2026-04-10T12:59:33 EDT -04:00 INFO Task: SMS
This issue occurs when the vsan-health service user is not explicitly granted 'read' access to the vpxd-extension VECS store, often following a certificate replacement or vCenter upgrade.
Grant read access for vsan-health in vpxd-extension VECS store.
/usr/lib/vmware-vmafd/bin/vecs-cli store get-permissions --name vpxd-extensionExpected output format:# /usr/lib/vmware-vmafd/bin/vecs-cli store get-permissions --name vpxd-extensionPERMISSIONS FOR STORE: [vpxd-extension]OWNER : rootUSER ACCESSvlcm readwcp readdeploy readinfraprofile writeupdatemgr readvsphere-ui readvpxd readanalytics readvsm readvsan-health readimagebuilder readcontent-library readeam readsps writevstatsuser read/usr/lib/vmware-vmafd/bin/vecs-cli store permission --name vpxd-extension --user vsan-health --grant read