Error Message : Not a CA Cert
certificate-manager.log
file, you see entries similar to:YYYY-MM-DDT<time> INFO certificate-manager Replacing Root Cert using Custom CA...
</time>YYYY-MM-DDT<time> INFO certificate-manager Running command :- ['/usr/lib/vmware-vmca/bin/certool', '--rootca', '--cert', '/tmp/root_signing_chain.cer', '--privkey', '/tmp/vmca_issued_key.key', '--server', 'localhost']
</time>YYYY-MM-DDT<time> INFO certificate-manager Command output :-
</time>Error: 70011, VMCAAddRootCertificatePrivate() failedStatus : Failed
Error Code : 70011
Error Message : Not a CA Cert
YYYY-MM-DDT<time> ERROR certificate-manager Error: 70011, VMCAAddRootCertificatePrivate() failedStatus : Failed
</time>Error Code : 70011
Error Message : Not a CA Cert
YYYY-MM-DDT<time> ERROR certificate-manager Error while performing Cert Replacement operation, please see /var/log/vmware/vmcad/certificate-manager.log for more information.
</time>YYYY-MM-DDT<time> ERROR certificate-manager {
</time>"resolution": null,
"detail": [
{
"args": [
"Error: 70011, VMCAAddRootCertificatePrivate() failedStatus : Failed\nError Code : 70011\nError Message : Not a CA Cert\n"
],
"id": "install.ciscommon.command.errinvoke",
"localized": "An error occurred while invoking external command : 'Error: 70011, VMCAAddRootCertificatePrivate() failedStatus : Failed\nError Code : 70011\nError Message : Not a CA Cert\n'",
"translatable": "An error occurred while invoking external command : '%(0)s'"
},
"Error while performing certool rootca command"
],
"componentKey": null,
"problemId": null
}
YYYY-MM-DDT<time> INFO certificate-manager Performing rollback of Root Cert...</time>
certificate-manager.log
file is located at:C:\ProgramData\VMware\vCenterServer\logs\vmca\certificate-manager.log
/var/log/vmware/vmcad/certificate-manager.log
openssl x509 -in root_signing_cert.cer -text -noout | grep CA\:
C:\Program Files\VMware\vCenter Server\openSSL\openssl x509 -in C:\Certs\root_signing_cert.cer -text -noout | findstr CA:
openssl req -in /tmp/vmca_issued_csr.csr -noout -text | grep -A4 "Requested Extensions"
command on the vCenter Server Applaince displays:Requested Extensions:
X509v3 Subject Alternative Name:
email:[email protected], DNS:vcsa.example.com
X509v3 Subject Key Identifier:
##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##