Symptoms:
Status : 0% Completed [Publishing Root cert...]
Status : 0% Completed [Operation failed, performing automatic rollback]
Error while replacing Machine SSL Cert, please see C:\ProgramData\VMware\vCenterServer\logs\vmca\certificate-manager.log
for more information.
Performing rollback of Machine SSL Cert...
certificate-manager.log
file indicates that the dir-cli
command to publish the trusted cert failed and you see entries similar to:[YYYY-MM-DDTHH:MM] INFO certificate-manager</time> Running command : ['C:\\Program Files\\VMware\\vCenter Server\\vmafdd\\dir-cli.exe', 'trustedcert', 'publish', '--cert', 'C:\\certs\\machineSSL\\cachain.cer', '--password', '*****']
[YYYY-MM-DDTHH:MM] INFO certificate-manager Command output :-
[YYYY-MM-DDTHH:MM] ERROR certificate-manager
[YYYY-MM-DDTHH:MM] ERROR certificate-manager Error while replacing Machine SSL Cert, please see C:\ProgramData\VMware\vCenterServer\logs\vmca\certificate-manager.log for more information.
[YYYY-MM-DDTHH:MM] ERROR certificate-manager {
"resolution": null,
"detail": [
{
"args": [
""
],
"id": "install.ciscommon.command.errinvoke",
"localized": "An error occurred while invoking external command : ''",
"translatable": "An error occurred while invoking external command : '%(0)s'"
},
"Error while publishing cert using dir-cli."
</time></time></time></time>],
"componentKey": null,
"problemId": null
}
certificate-manager.log
file is located in these locations:
C:\ProgramData\VMware\vCenterServer\logs\vmca\certificate-manager.log
/var/log/vmware/vmcad/certificate-manager.log
VMware vCenter Server 6.0.x
VMware vCenter Server 6.5.x
VMware vCenter Server 6.7.x
All Intermediate(s) and the Root CA certificates must be published into the trusted store in VMware Endpoint Certificate Store for the script to complete.
This issue is resolved in VMware vCenter Server 6.0.0b, available at Broadcom Support.
For vCenter Server Appliance 6.x: