Log Management appliances show old certificates after replacement in Fleet Management VCF 9.1
search cancel

Log Management appliances show old certificates after replacement in Fleet Management VCF 9.1

book

Article ID: 443549

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

  • Successfully replace certificate for Log Management in Fleet Management using a configured CA.
  • The component FQDN in Fleet Management displays the correct CA-signed certificate.
  •  Browsing to individual Log Management appliance FQDNs, IP addresses, or the VIP continues to show the old internally generated certificate.
  • This occurs despite the replacement process completing without errors in the UI.

Environment

  • VMware Cloud Foundation 9.1.x
  • VCF Operations / Fleet Management 9.1.x
  • VCF Operations for Logs 9.x

Cause

Starting with VMware Cloud Foundation 9.1, Log Management transitions from a standalone appliance-based deployment to an integrated service model. The certificate replacement workflow in Fleet Management targets the new Log Management service FQDN. The legacy individual appliances and their associated Load Balancer VIP are deprecated components from previous versions and do not receive the new certificate during the Fleet Management operation.

Resolution

Decommission the VCF operation legacy appliances as they are no longer required in the service-based architecture.
Refer to the Upgrade Sequence and Related Issues for VMware Cloud Foundation and vSphere Foundation 9.1 for more details.