Error: certificate_unknown(46) appears during VCF Operations for Networks Upgrade
search cancel

Error: certificate_unknown(46) appears during VCF Operations for Networks Upgrade

book

Article ID: 448425

calendar_today

Updated On:

Products

VCF Operations VCF Operations for Networks

Issue/Introduction

  • While upgrading VCF from version 9.0.x to version 9.1, the process fails while running pre-checks against VCF Operations for Networks.
  • A similar error message to the one below is displayed in the UI:
An unexpected error occurred in step nodes_health_check. Reference Code: 14926D9A. Please contact support with this reference code.   
Detail: I/O error on GET request for "https://<IP>/api/management/nodes": Failed to obtain authentication token:   
Failed to obtain OpsNetworks authentication: I/O error on POST request for any api on vRNI for example: "https://<IP>/api/auth/login": certificate_unknown(46)

Environment

  • VMware Cloud Foundation (VCF) 9.0
  • VCF Operations for Networks 9.0.x

Cause

  • Outdated Fleet Lifecycle Manager (LCM) and SDDC LCM components are causing validation or trust failures during the node health check validation against the replaced certificates.
  • SSL handshake failure due to VCF Operations for Networks certificate not being trusted by the VCF Operations fleet.

Resolution

To resolve the issue, follow the steps below:

  1. Upgrade Fleet LCM and SDDC LCM to version 9.1.0.400.
  2. Re-run the VMware Aria Operations for Networks precheck.
  3. Proceed with the Operations for Networks upgrade via the console once the precheck passes.

If the issue persists, open a support ticket with Broadcom referencing KB 443169 in the description.