Error: frpc monit process fails to verify certificate authority on ensemble_stitching VM in Platform Services tile
search cancel

Error: frpc monit process fails to verify certificate authority on ensemble_stitching VM in Platform Services tile

book

Article ID: 452865

calendar_today

Updated On:

Products

VMware Tanzu Platform - Hub

Issue/Introduction

  • Users report conditions like:
    • "ensemble_stitching bosh job wont start"
    • "the frpc monit job wont start"
  • Updates to Platform Services tile fail on the ensemble_stitching VM, which is stuck in 'failing' state.
  • From an SSH session to the failing VM, monit summary shows the frpc process in "Execution failed" state:

    ensemble_stitching/########-####-####-####-6df11bcd9a2f# monit summary
    The Monit daemon 5.2.5 uptime: 59m

    Process 'ensemble-stitching'     running
    Process 'frpc'                   Execution failed
    Process 'opamp-server'           running
    Process 'bosh-dns'               running
    Process 'bosh-dns-resolvconf'    running
    Process 'bosh-dns-healthcheck'   running
    Process 'system-metrics-agent'   running
    System 'system_########-####-####-####-dc087df6454b' running

  • The /var/vcap/sys/log/frpc/frpc.stdout.log shows warnings like:

    2026-08-19 14:04:16.649 [I] [sub/root.go:178] frpc service for config file [/var/vcap/jobs/frpc/config/frpc.toml] stopped
    login to the server failed: tls: failed to verify certificate: x509: certificate signed by unknown authority. With loginFailExit enabled, no additional retries will be attempted

  • This typically occurs after a TLS certificate rotation for Hub and Foundations.

Environment

VMware Tanzu Hub

Platform Services Tile

Cause

The CA certificate chain in Ops Manager > Platform Services Tile > Tanzu Hub CA Certificate is incorrect, incomplete, or expired. The frpc service cannot verify the connection because the intermediate or root certificates are missing from the provided chain.

Resolution

  1. Log in to Operations Manager.
  2. Navigate to Platform Services Tile > Tanzu Hub CA Certificate.
  3. Confirm the certificate chain is correctly formatted in PEM format.
  4. Ensure the chain includes the full hierarchy: Intermediate(s) > Root CA.
  5. Save changes and select Apply Changes for the Platform Services tile.
  6. If the process does not recover, SSH to the ensemble_stitching VM and run monit restart frpc.

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.