Standby cell instability during SSL certificate updates in VMware Cloud Director
search cancel

Standby cell instability during SSL certificate updates in VMware Cloud Director

book

Article ID: 450610

calendar_today

Updated On:

Products

VMware Cloud Director

Issue/Introduction

When updating SSL/TLS certificates in a multi-cell VMware Cloud Director environment, the deployment becomes unstable or encounters errors when attempting to apply updates or perform cluster failovers using standby cells.

The certificate update only succeeds when applied directly to the active primary cell. Subsequent failover operations to a standby cell fail or leave the standby node unusable.

Environment

VMware Cloud Director 10.x

Cause

Standby cells cannot properly bind or synchronize updated cluster-wide certificate stores while in a secondary role. Modifying standby nodes directly bypasses the expected appliance configuration workflows driven by the primary cell, resulting in database and configuration state desynchronization upon failover

Resolution

To resolve the failure and restore cluster stability, update the primary node first and redeploy the standby nodes so they receive a clean, synchronized state:

  1. Log in to the active primary VMware Cloud Director cell.

  2. Update the SSL/TLS certificate on the primary cell via the Provider UI or CLI.

  3. Unregister and remove the unstable standby cells from the Cloud Director cluster. Unregister a Running Standby Cell in Your VMware Cloud Director Database High Availability Cluster

  4. Deploy new standby cell. The newly created standby nodes will automatically pull and apply the correct certificate configuration from the primary node. VMware Cloud Director Appliance Deployments and Database High Availability Configuration

  5. Verify cluster health and perform a test failover to confirm standby cell stability.