Error: VCF_LCM_IAM_500_PUBLIC_KEYS_FETCHING_ERR VCF Management failed to load VCF Operations
search cancel

Error: VCF_LCM_IAM_500_PUBLIC_KEYS_FETCHING_ERR VCF Management failed to load VCF Operations

book

Article ID: 447487

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

  • The VCF Management interface fails to load, preventing the administration of VCF components and the execution of upgrade workflows. This occurs when attempting to access lifecycle details or fetch an upgrade plan for VCF Operations (formerly Aria Suite) 9.1.0.

  • When attempting to view components in the VCF Operations Lifecycle UI after a certificate replacement or upgrade to VCF 9.1, the following symptoms occur:

    The UI displays the error: Unable to fetch tasks. Failed to load public keys set from https://####/suite-api/jwks. Retry the operation. If the issue persists, contact Broadcom Support.

  • VCF components are missing from the Lifecycle view.

    Logs in VCF Fleet LCM (/var/log/vmware/vcf/fleet-lcm/...) show: SSL/TLS handshake failure for GET https://####/suite-api/jwks: certificate unknown (46).

    Logs indicate: Certificate with kid=#### not found in trust store.

  • Components tab in VCF Management appears blank or fails to populate.

Environment

  • VMware Cloud Foundation 9.1

  • VCF Operations 9.1

Cause

The internal trust store used by Fleet Lifecycle Manager (LCM) and SDDC LCM to validate VCF Operations tokens does not automatically refresh following a certificate replacement on VCF Operations nodes. This results in a TLS handshake failure during security key synchronization.

Resolution

This issue will be fixed in future release. For further assistance contact Broadcom technical Support