Unable to connect to software depot on a new deployment of VCF 9.1
search cancel

Unable to connect to software depot on a new deployment of VCF 9.1

book

Article ID: 449248

calendar_today

Updated On:

Products

VMware SDDC Manager / VCF Installer

Issue/Introduction

Attempting to configure a connected software depot fails. Outbound IPv6 internet access is disabled, and the environment sits behind an explicit proxy with TLS/SSL interception. The new containerized Software Depot in VCFMS (VCF Management Services) did not natively trust the proxy's certificate chain, and the following error is displayed:

 

Environment

VCF 9.1x

Cause

The FDS (Fleet Download Service) container logs showed certificate handshake failures:
Caused by: java.security.cert.CertPathBuilderException: Unable to find certificate chain.
The customer applied the workaround in KB 442978 to import the proxy certificates. However, on step 6 (which states the UI will go blank and services will restart in ~15 minutes), the Software Depot UI remained blank/inaccessible for over an hour.

Resolution

1. The original issue of the Software Depot not trusting the inspection proxy certificate was resolved by applying KB 442978.

2. The subsequent VMSP/UI outage was resolved by deleting and restarting the vmsp-gateway-2 pod, allowing it to boot cleanly and ingest the newly applied certificate trust.

3. Once the gateway restarted, the Operations Console UI loaded successfully for both the Software Depot and VCF Services.

4. With the proxy certificate trusted and routing restored, the Software Depot successfully connected to the online Broadcom portal and synced the VCF metadata.