Cannot reset a previously configured OpenSSL CA in VCF Operations 9.0
search cancel

Cannot reset a previously configured OpenSSL CA in VCF Operations 9.0

book

Article ID: 453182

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

Unable to reset, remove, or undo an OpenSSL certificate authority once it has been configured under the Certificates section in the Fleet Management, in VCF Operations interface.

Environment

  • VCF Fleet Management 9.0.x
  • VCF Operation 9.0.x

Cause

OpenSSL certificate authority (CA) is used to issue a certificate, removing its underlying CA data will break both the "Manual Renew" and "Auto-Renew" functionalities within the system. To prevent unexpected disruptions to certificate lifecycle management, the ability to delete or clear CA data is intentionally disabled. 

Resolution

This is an expected behavior. There is currently no supported "reset" or "undo" function for a created OpenSSL certificate authority (CA) within VCF Operations.

Workaround:

  • While you cannot delete the CA, you can safely overwrite it.
  • To implement a new CA, simply reconfigure or recreate the OpenSSL CA by entering the new properties directly into the existing OpenSSL configuration form. Saving these new details will override the previous configuration.

Additional Information

 
Note: If you are interested in requesting that other options be added, you can vote for Update the VCF 9.0.x UI/API to reconfigure OpenSSL for Fleet Mgmt->Certificates->Configure CA->MSCA