vCenter Server services fail to start due to missing signing certificates
search cancel

vCenter Server services fail to start due to missing signing certificates

book

Article ID: 445106

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

  • vCenter Server is using custom CA machine SSL certificate 
  • After reboot the services are not coming up fully 
  • vmon.log shows:
    [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: unable to get issuer certificiate 
  • When using the vCert utility to generate a certificate report the machine SSL status shows:
    MISSING CA
  • Enhanced Linked Mode is non-functional/unavailable (if enabled)

Environment

VMware vCenter Server 8.x

Cause

  • The machine SSL cert did not contain the full valid chain with root and intermediate certificates when it was installed 
  • Or the root/intermediate certificates were removed from the TRUSTED_ROOTS store

Resolution

Option 1: 

Option 2: 

  • Use the vCert utility to generate a new CSR for a custom CA machine SSL certifiacte 
  • Ensure to have the complete chain when importing the machine SSL certificate file in the order of:
    Leaf certificate > Intermediate certificate > Root Certificate 

Option 3:

  • Use the vCert utility to replace the machine SSL certificate with self-signed VMCA certificate