When the configured Microsoft CA is an intermediate CA to another root CA in VCF 9.1, replacing component certificates will either fail or lead to issues in the component.
vc.cert.replacement.error Certificate task REPLACE_CERTIFICATE for ##### has failed. Error message: vCenter Certificate replacement task failed.Bulk Task ID: #####,ReplaceCertTask ID: ######. Exception: Failed to execute request PUT https://<FQDN>/api/vcenter/certificate-management/vcenter/tls with exception{"error_type":"ERROR","messages":[{"args":["No issuer certificate for certificate in certification path found."],"default_message":"Exception found (No issuer certificate for certificate in certification path found.)","id":"com.vmware.certificatemanagement.error"}]}
esx.cert.replacement.errorCertificate task REPLACE_CERTIFICATE for '####' has failed. Error message: Unexpected error during certificate replacement for for bulkTakId = #####, subTaskId = ##### on ESXi host #####. Cannot change the host configuration.Authenticity of the host's SSL certificate is not verified."certificate.upload.errorCertificate task REPLACE_CERTIFICATE for ##### has failed. Error message: Unable to upload certificate against CSR ID ###### on NSX for replace certificate operation with error message : Certificate chain validation failed. Make sure a valid chain is provided in order leaf,intermediate,root certificate.. Please check VIM adapter logs and task status for more details.unexpected.response.codeCertificate task REPLACE_CERTIFICATE for '####' has failed. Error message: Failed to perform specified operation on SDDC manager. Following conditions do not match - The Certificate Chain '#####' validation failed due to 'Signature does not match.'certificate.replace.failedCertificate task REPLACE_CERTIFICATE for <FQDN> has failed. Error message: Certificate chain is not valid.This is a known issue affecting VCF 9.1 GA.
This issue is fixed in VCF Operations 9.1.0.0200. See the Release Notes for more information
To workaround this issue in VCF Operations 9.1.0.0000 and 9.1.0.0100, see the steps below.
For any certificate that has been replaced or needs to be replaced with this Microsoft CA should be done manually:
Note: If the certificates do not update in the browser/UI immediately after the manual import reboot the Component VM and retry the steps above.