VCF Download Tool (v9.1.0 and higher) may fail with the error below- error while verifying signatures for vCenter upgrade information files:
"BUNDLE_SIGNATURE_VERIFICATION_FAILED"
This issue occurs when component-specific metadata within the local depot store becomes stale or mismatched, preventing the tool from validating the file against the trusted certificate (lcm_bundle_trusted_sig.cert), even if the global product catalog is synchronized
c:\temp\...)Stale or mismatched metadata files located within the specific component subdirectories of the local depot store prevent the tool from validating signatures during the download process.
To resolve this issue, force the VCF Download Tool to re-synchronize the specific component metadata by renaming the affected directories.
c:\temp\Vmware-depot-2\).rename c:\temp\Vmware-depot-2\local\tmpDir tmpDir.OLDc:\temp\Vmware-depot-2\PROD\COMP\VCENTER\vmw\[component-uuid]\.OLD.vdt.log file located in the logs subdirectory for specific Java stack traces or file access permissions.