Supervisor Certificate Auto Renewal fails with "Errors occurred during automatic CPVM certificate rotation"
search cancel

Supervisor Certificate Auto Renewal fails with "Errors occurred during automatic CPVM certificate rotation"

book

Article ID: 442519

calendar_today

Updated On:

Products

VMware vSphere Kubernetes Service

Issue/Introduction

The following error message is triggered in the vCenter Server UI or logs:

"Errors occurred during automatic CPVM certificate rotation."

The automatic certificate renewal process is originally designed to be triggered 180 days prior to the certificate's expiration date.
If it fails, the system continuously retries the rotation process every 6 hours.

Environment

vCenter Server 8.0 Update 3 (versions prior to 8.0 U3j)

Cause

This issue occurs due to a known software defect in the Supervisor certificate auto-renewal feature in vCenter Server 8.0 U3.

Resolution

Permanent Fix:

This issue is resolved in vCenter Server 8.0 U3j (8.0.3.00900) and later releases. Please upgrade your vCenter Server to apply the permanent fix.

Workaround:

To resolve the active alert and renew the certificates in earlier versions, you must manually rotate the Supervisor certificates using the latest certmgr binary.
Please follow the instructions provided in the KB article below:

KB - Replace vSphere with Tanzu Supervisor Certificates

Additional Information

KB - Auto Cert Renew for VKS Cluster