This article will help to remove the Certificate Status error by identifying the expired/expiring certificates and direct users to the right articles to replace the certificate.
Alarm alarm.CertificateStatusAlarm
There are certificate that expired or about to expire
/var/log/vmware/vpxd/vpxd.log
will show the following message:[YYYY-MM-DDTHH:MM:SS] warning vpxd[30469] [Originator@6876 sub=Main opID=CheckCertificateExpiry-57e82b11] Certificate [Subject: <Certificate Subject>] from store <VECS Store Name> will expire on YYYY-MM-DD HH:MM:SS
[YYYY-MM-DDTHH:MM:SS]
warning vpxd[30469] [Originator@6876 sub=Main opID=CheckCertificateExpiry-57e82b11] Certificate [Subject: <Certificate Subject>] from store <VECS Store Name> will expire on YYYY-MM-DD HH:MM:SS
vpxd.cert.threshold
vpxd.certmgmt.certs.hardThreshold
vpxd.certmgmt.certs.pollIntervalDays
Review the certificate expiration values within each Keystore of the VMware Endpoint Certificate Store (VECS) to determine which certificate is close to its expiration date or that has already expired.
MACHINE_SSL_CERT VECS
/usr/lib/vmware-vmafd/bin/vecs-cli entry delete --store MACHINE_SSL_CERT --alias __MACHINE_CSR -y
Solution Users VECS - machine, vsphere-webclient, vpxd, vpxd-extension
SMS VECS
TRUSTED_ROOTS VECS
Data-encipherment VECS
BACKUP_STORE VECS
/usr/lib/vmware-vmafd/bin/vecs-cli entry list --store BACKUP_STORE --text
/usr/lib/vmware-vmafd/bin/vecs-cli entry getcert --store BACKUP_STORE --alias <Alias Name> --output <output folder>
/usr/lib/vmware-vmafd/bin/vecs-cli entry getcert --store BACKUP_STORE --alias bkp___MACHINE_CERT --output /certificates/old_machine.crt
/usr/lib/vmware-vmafd/bin/vecs-cli entry delete --store BACKUP_STORE --alias <Alias Name> -y
/usr/lib/vmware-vmafd/bin/vecs-cli entry delete --store BACKUP_STORE --alias bkp___MACHINE_CERT -y
Note
For STS certificate Expired/Expiring/Signing Certificate
Note: STS/Signing Certificate is not stored in VECS store, hence not covered in vCenter Server alarms. Please verify this Certificate by following the above steps before proceeding with the replacement of other Certificates stored in VECS store as replacement of these certificates will fail if STS certificate is already expired.