VCF Automation (VCFA) import into VCF Operations Fleet Lifecycle component has failed
search cancel

VCF Automation (VCFA) import into VCF Operations Fleet Lifecycle component has failed

book

Article ID: 446670

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

  • Importing VCFA is failing with error 'Failed to validate certificate. Internal Server Error for service Fleet Build. Verify logs for service Fleet Build.'
  • /storage/log/vcops/log/analytics_bouncycastle.log in VCF operations shows the error: 
    Jun 15, 2026 6:29:48 PM org.bouncycastle.jsse.provider.ProvTlsClient notifyAlertRaised
    WARNING: [client ##### @######] raised fatal(2) internal_error(80) alert: Failed to read record
    java.net.SocketException: Connection reset

Environment

VCF Operations 9.1

VCF Automation 9.x

Cause

Multiple issues contribute to this failure:

  • Ports 443,22 and 6443 are closed on the firewall, preventing communication between components.
  • The vmware-system-user has expired on one or more VCF Automation nodes .

Resolution

  1. Ensure ports 443, 22 and 6443 are open between the Fleet Management and VCF Automation components. Refer to VMware Ports and Protocols for a full list of requirements.
  2. Log in to each VCF Automation node and verify the status of the vmware-system-user. Reset expired passwords immediately Resetting the vmware-system-user password for VCF Identity Broker & VCF Automation

Additional Information

VCF Automation 9.0.x to 9.1 upgrade precheck failure during certificate chain validation