Attempting to replace the VCF Automation (VCFA) certificate from the VCF Operations UI fails.
The task fails specifically during the "Push capabilities to VCF Automation" at stage 2.
The UI and logs display the following error:
Error Code: LCMVCFA00007Error occurred while pushing capabilities in VCF Automationcom.vmware.vrealize.lcm.vcfa.common.exception.UnableToGetVcfaTokenException: illegal_parameter(47)
Despite the task failure in VCF Operations, the certificate is successfully replaced in the background, and the VCF Automation component shows the new certificate as "Active".
VCF Operations 9.1
VCF Automation 9.1
Internal communication between VCF Operations and VCF Automation is incorrectly being routed through the globally configured HTTP proxy. Because the global proxy cannot reach or resolve these internal VCF components, the connection fails, which causes the capability push task to fail during the certificate replacement workflow.
Broadcom is aware of this issue. A fix has been identified and will be included in the upcoming release.
To bypass this issue and successfully complete the certificate replacement in VCF 9.1, temporarily disable the global HTTP proxy:
In the VCF Operations UI, navigate to Operations Console > Administration > Global Settings > Global Proxy.
Take note of the current proxy configuration, and then temporarily delete the proxy settings.
Navigate back to the failed VCFA certificate update task and Retry it.
Allow the task to complete successfully.
Once the certificate has been applied, return to Global Proxy settings and re-configure/re-enable the proxy using the details noted in step 2.