VCF component upgrades from 5.2 and 9.0.x to 9.1 fails due to missing entries in SSL certificate Subject Alternative Name (SAN) extension
search cancel

VCF component upgrades from 5.2 and 9.0.x to 9.1 fails due to missing entries in SSL certificate Subject Alternative Name (SAN) extension

book

Article ID: 449907

calendar_today

Updated On:

Products

VMware Cloud Foundation

Issue/Introduction

Upgrade of management components to VMware Cloud Foundation 9.1 fails If the component SSL certificate(s) is missing the Subject Alternative Name (SAN) extension values.

Environment

VCF 9.0

VCF 9.1

Cause

VCF 9.1 introduces a significant architectural change by moving lifecycle management from the deprecated VCF Operations Fleet Management Appliance to the newly integrated Fleet Lifecycle service.  VCF 9.1 now enforces strict certificate validations that previous versions did not.
If your existing certificates are non-compliant (e.g., they only contain the IP address and are missing the FQDNs), the automated inventory migration and registration into Fleet Lifecycle will fail. This will block your VCF 9.1 upgrade.

Resolution

Before initiating the upgrade, check your certificates. If the SAN fields are incomplete, you must replace them with CA-signed certificates that have properly populated SAN fields. The SAN field must include the FQDNs/IP addresses for every node in the cluster

You can handle this manually for following the steps in Aria Suite Lifecycle document : https://techdocs.broadcom.com/us/en/vmware-cis/aria/aria-suite-lifecycle/8-14/vmware-aria-suite-lifecycle-installation-upgrade-and-management-8-14/configuring-vmware-aria-suite-lifecycle/manage-certificates.html

Additional Information

https://knowledge.broadcom.com/external/article/440296/error-unable-to-reach-vcf-operations-nod.html