Generating a Certificate Signing Request (CSR) for vCenter from the SDDC Manager UI fails almost immediately.
In /var/log/vmware/vcf/operationsmanager/operationsmanager.log, the following error is observed:
DEBUG [vcf_om,,] Processing localizable exception Resource(s) [vCenter-FQDN], is/are not active.
ERROR [vcf_om,,] [APLHJU] CERTIFICATE_CSR_GENERATION_FAILED Resource(s) [vCenter-FQDN], is/are not active.
com.vmware.vcf.certmgmt.common.exception.CertMgmtRestException: Resource(s) [vCenter-FQDN], is/are not active.
VCF 5.x
The SDDC Manager platform database reflects an incorrect status for the vCenter resource. If the vCenter status is set to ERROR or any status other than ACTIVE, the Certificate Management service will reject the CSR generation request because it perceives the resource as unavailable for management operations.
Log in to the SDDC Manager appliance via SSH as vcf and switch to root.
If the status column for the failing vCenter shows ERROR open support case with Broadcom support