Failed to connect to authorization server" or "Failed to connect to Broadcom OAuth Authorization serverjavax.net.ssl.SSLHandshakeException: PKIX path building failed:
sun.security.provider.certpath.SunCertPathBuilderException:
unable to find valid certification path to requested targetTLS/HTTPS interception), the firewall intercepts outbound connections to online VCF software depot URLs (e.g. dl.broadcom.com, eapi.broadcom.com) and re-encrypts the traffic using its own CA-signed certificate instead of the real Broadcom certificate. Since the Software Depot trust store does not contain the firewall's Root CA/Intermediate CA, the TLS handshake fails and the online depot cannot be configured or used.vmsp-utility.py script Build > Lifecyle > VCF Management > Components > VCF Services Runtimevmsp-utility script to the Control Plane node's /home/vmware-system-user/ directory.vmware-system-user (If password unknown follow steps in, "Resetting the vmware-system-user password for VMware Cloud Foundation Services Runtime")sudo -i
root@vsp-6lq8s [ /home/vmware-system-user ]# python vmsp-utility.py
══════════════════════════════════════════════════════════════════
VCF Management Service Utility
══════════════════════════════════════════════════════════════════
Please ensure script is running on a Controller node
vmware-system-user SSH password is required
KUBECONFIG already set to /etc/kubernetes/admin.conf
Resolving Node Host...
NODE_HOST detected: https://192.168.1.213:5480
Resolving VSP FQDN...
VSP FQDN detected: vsp.vcf.lab
Please enter the SSH password for vmware-system-user:
Successfully generated token!
Authenticating to VSP ([email protected])...
VSP token generated.
VSP component ID: 1d588015-dd49-4331-a181-017cc508592e
1. Show proxy configuration
2. Configure proxy
3. Remove proxy
4. Add certificates into truststore
5. List certificates in truststore
6. Quit
Select one of the following options: 4
─── Add Certificates into Truststore ───
Path to PEM chain file: /home/vmware-system-user/root.crt