This issue is known to VMware by Broadcom. In the interim, you must bypass the automated Microsoft CA URL process and manually generate and import the full certificate chain. Follow these steps to resolve the issue:
- Generate a CSR: Log into the VCF Operations UI as local user
admin and navigate to the certificate management section to generate a new Certificate Signing Request (CSR). - Download the CSR: Export the generated request using the
Download CSRs option. - Manually Generate the Certificate: Submit the downloaded CSR to your Microsoft CA to get it signed.
Note: You must ensure that the full certificate chain (leaf, intermediate, and root) is exported from the CA. - Import Certificates: Return to the VCF Operations UI and upload the complete, newly signed certificate chain using the
Import Certificates option. - Replace Certificates: Finalize the process by selecting the
Replace with Imported Certificates option. This securely applies the new certificates with the complete chain of trust, resolving the TLS handshake errors and restoring Ops-Logs functionality.