Solution User certificates missing CA in vCenter Server
search cancel

Solution User certificates missing CA in vCenter Server

book

Article ID: 446684

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

  • vCenter Server services fail to start.
  • vCert report indicates that Solution User certificates (machine, vpxd, etc.) have a status of "MISSING CA."
  • vCenter Server patching fails due to certificate trust issues.

Environment

  • VMware vCenter Server 8.x
  • VMware vCenter Server 7.x

Cause

When vCert shows Solution User certificates MISSING CA, it typically indicates that the root CA previously used to issue those certificates was deleted or is no longer present in the VMware Directory.

Resolution

  1. Perform a file-level backup or take an offline snapshot of the vCenter Server before proceeding.
  2. Launch the vCert utility.
  3. Navigate to Option 3 (Manage certificates).
  4. Select Option 3 (Manage certificates).
  5. Select Option 9 (VMCA certificate).
  6. Select Option 2 (Replace CA certificates and reissue all certificates).
  7. Restart all services again to apply the new certificate chain.  New Solution Users certificates are created using the new CA certificate.  

Additional Information

vCert - Scripted vCenter expired certificate replacement

Contact Broadcom support