Log Forwarding fails from VLCR Connectors to VCF Operations for Logs due to SSL Certificate Trust Issues
search cancel

Log Forwarding fails from VLCR Connectors to VCF Operations for Logs due to SSL Certificate Trust Issues

book

Article ID: 440018

calendar_today

Updated On:

Products

VMware Live Recovery

Issue/Introduction

When attempting to configure or test log forwarding from VMware Live Recovery (VLCR) connectors to VCF Operations for Logs, the connection fails.

•    A "secure" connectivity test using curl -v from the VLCR connector to the VCF Operations for Logs API endpoint fails due to certificate validation errors.
•    An "insecure" connectivity test using curl -vkl (which ignores certificate checks) succeeds.
•    Log ingestion is not active despite the network path being functional.

Environment

VLCR 9.0.0.11 or newer

Cause

The VLCR appliances do not trust the SSL certificate presented by the VCF Operations for Logs instance. This typically occurs when the instance is using a self-signed certificate or a certificate chain that has not been properly imported into the connectors' trust store. The failure of the "secure" test and the success of the "insecure" test confirm a certificate trust mismatch.

Resolution

To resolve this issue, replace the existing certificate on the VCF Operations for Logs instance with a trusted CA-signed certificate.
Contact Broadcom support for detailed instructions

Additional Information

References:

VCF Operations for Logs Agent is unable to connect securely to Cloud Proxy Log Forwarder

Enable SSL communication in Aria Operations for Logs agent in SDDC Manager