Lifecycle manager fails to check image compliance for ESX - A general system error occurred - com.vmware.vcIntegrity.lifecycle.depots.VibDownloadErrorInfo.Resolution
com.vmware.vcIntegrity.lifecycle.depots.VibDownloadErrorInfo
search cancel

Lifecycle manager fails to check image compliance for ESX - A general system error occurred - com.vmware.vcIntegrity.lifecycle.depots.VibDownloadErrorInfo.Resolution
com.vmware.vcIntegrity.lifecycle.depots.VibDownloadErrorInfo

book

Article ID: 450991

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

When scanning an ESX host for compliance against an vSphere Lifecycle Image the process will fail and an error will be present in the UI:

A general system error occurred:
com.vmware.vcIntegrity.lifecycle.depots.VibDownloadErrorInfo.Resolution
com.vmware.vcIntegrity.lifecycle.depots.VibDownloadErrorInfo

In the vmware-vum-server.log file the following error is present: 

####-##-##T##:##:##.###-##:## error vmware-vum-server[98065] [Originator@6876 sub=httpDownload] [httpDownloadPosix 797] curl_easy_perform() failed: cURL Error: SSL peer certificate or SSH remote key was not OK, SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)

####-##-##T##:##:##.###-##:## error vmware-vum-server[98065] [Originator@6876 sub=DownloadMgr] [downloadMgr 705] Executing download job {140718387599312} throws error: curl_easy_perform() failed: cURL Error: SSL peer certificate or SSH remote key was not OK, SSL certificate OpenSSL verify result: self-signed certificate in certificate chain (19)

####-##-##T##:##:##.###-##:## error vmware-vum-server[98065] [Originator@6876 sub=DownloadMgr] [downloadMgr 813] Download failed for url: https://dl.broadcom.com/<token>/PROD/COMP/ESX_HOST/main/esx/vmw/vib20/esxio-update/VMware_bootbank_esxio-update_8.0.3-0.100.25429389.vib

Environment

vCenter Server 8.x

Cause

This is caused by a proxy server TLS inspection issue. 

Resolution

To resolve this issue use one of the methods below: 
 
1. Replace the MACHINE_SSL_CERT for the vCenter Server with a custom CA certificate trusted by the proxy 
- To replace the MACHINE_SSL_CERT for the vCenter Server see KB316601
 
2. Upload the proxy certificate to the vCenter Server VECS certificate store
- To upload the certificate from the proxy to the vCenter VECS certificate store see KB336092
 

Additional Information

Machine SSL certificate renewal using Custom Certificate Authority (CA) in vCenter Server - https://knowledge.broadcom.com/external/article/316601

"cannot authenticate SSL certificate for proxy" in Content Library for vCenter HTTPs Proxy Support - https://knowledge.broadcom.com/external/aticle/336092