When attempting to configure a Microsoft Certificate Authority (CA) within the VCF Operations console for certificate management, the operation fails.
Symptom:
Failed to update certificate authorities. Please verify the provided input values and try again.operationsmanager.log on the SDDC Manager typically shows a java.net.SocketException: Connection reset or SSLPeerUnverifiedException when calling the MicrosoftCaPlugin.VCF Operations 9.1.0.x
Microsoft Certificate Authority (IIS-based Web Enrollment)
The configuration failure is often caused by a combination of the following factors in the VCF 9.1 architecture:
/certsrv) is not configured to allow Basic Authentication, which is required for the automated API calls from VCF Operations.Require" or "Accept" client certificates, causing a connection reset when VCF Operations attempts to connect without a client-side certificate.To resolve this issue, perform the following steps:
Prepare Microsoft CA for Basic Authentication:
iisreset from an administrative command prompt.Verify Service Account and Template:
https://<ca_fqdn>/certsrv URL from a browser.Upgrade to VCF Operations 9.1.0.0400:
Re-attempt Configuration:
If an upgrade is not immediately possible, ensure the root and subordinate CA certificates are manually trusted by the SDDC Manager:
vcf and switch to root.