Symptoms:
[YYYY-MM-DDTHH:MM:SS] [ERROR] -nio-127.0.0.1-5090-exec-695 xxxxxx c.vmware.certificates.client.controllers.VcCertificateController Internal server error occurred while accessing Certificate services: com.vmware.vapi.std.errors.Error: Error (com.vmware.vapi.std.errors.error) => { messages = [LocalizableMessage (com.vmware.vapi.std.localizable_message) => { id = com.vmware.certificateauthority.error, defaultMessage = Internal Server Error (Error occurred while getting certificate VMCA_ROOT_CA_MISSING), args = [Error occurred while getting certificate VMCA_ROOT_CA_MISSING]
VMware vCenter Server 8
The certificatemanagement-svcs encounters a VMCAException because the VCHA cluster state interferes with the service's ability to query the local VMCA root.
As per KB https://knowledge.broadcom.com/external/article/403973/vcenter-machine-ssl-certificate-replacem.html, the VCHA needs to be disabled before rotating certificate.
Disable VCHA before rotating certificate:
KB https://knowledge.broadcom.com/external/article/403973/vcenter-machine-ssl-certificate-replacem.html
Remove VCHA:
KB https://knowledge.broadcom.com/external/article/393136/remove-vcenterha-option-fails-with-gener.html