ESXi Host Certificate Expiration Data Mismatch in VMware Aria Operations/VCF Operations
search cancel

ESXi Host Certificate Expiration Data Mismatch in VMware Aria Operations/VCF Operations

book

Article ID: 455655

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite) VCF Operations

Issue/Introduction

This article addresses an issue where ESXi host certificate expiration data in VMware Aria Operations/VCF Operations does not accurately reflect the data from vCenter Server. This typically manifests as stale or incorrect expiration dates in the "Certificate Summary" properties.

Symptoms

  •  The "Certificate Summary | No. of days to expire" property displays incorrect values.
  •  The "Certificate Summary | End Date" property does not match the actual certificate expiration date seen in vCenter.
  •  Multiple ESXi hosts are affected when managed by the same Cloud Proxy or Collector.

Environment

  • VMware Aria Operations 8.18.x
  • VCF Operations 9.0.x

Cause

A race condition exists in the VMware Infrastructure Health (VIH) adapter within the cloud proxy or collector when it is configured to collect data for multiple vCenter servers. This race condition causes the certificate collection process to trigger for only one vCenter instance while skipping others.

Resolution

Broadcom is aware of this issue and a permanent fix is targeted for a future release of VMware Aria Operations/VCF Operations. Subscribe to this knowledge base article to get updates on this issue.

Note: This issue does not impact VCF Operations 9.1

Workaround

To resolve the mismatch and force a collection of certificate data, follow these steps:

1. Identify the vCenter servers which hosts the affected ESXi hosts for which the certificate details are not updated

2. Reconfigure these specific vCenter adapters to use a dedicated collector/cloud proxy temporarily

  • In the  Aria Operations/VCF Operations UI, go to Administration>>Integrations
  • Edit the affected vCenter adapter
  • Under collector/group section, select a individual collector or cloud proxy instead of a group
  • Save the configuration

3. Restart the VMware Infrastructure Health Adapter instance:

  • In the  Aria Operations/VCF Operations UI, go to Infrastructure Operations>>Configurations>>Inventory Management
  • Expand Adapter Instances and select VMware Infrastructure Health Adapter instance
  • Select the Infrastructure Health Adapter of the collector/cloud proxy that was configured for the affected vCenter.
  • Restart the collection by select Stop Collecting and Start Collecting

4. Wait for at least 2 collection cycles(10 minutes) and validate the certificate details in VMware Aria Operations/VCF Operations

5. After applying the above for all the affected vCenter adapters, revert the change by selecting a collector/cloud proxy group as per the requirement