"ERROR certificate-manager 'lstool get-site-id' failed: 1", Certificate Replacement with Custom Certificate Fails on vCenter Server
search cancel

"ERROR certificate-manager 'lstool get-site-id' failed: 1", Certificate Replacement with Custom Certificate Fails on vCenter Server

book

Article ID: 344262

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

  • Certificate Replacement with Custom Certificates fails on vCenter Server 6.x with lstool get-site-id failed error message
    certificate-manager 'lstool get-site-id' failed: 1"
  • Certificate Manager log shows similar to below messages in the location /var/log/vmware/vmcad/certificate-manager.log
    ERROR certificate-manager Error while replacing Machine SSL Cert, please see /var/log/vmware/vmcad/certificate-manager.log for more information.
    ERROR certificate-manager 'lstool get-site-id' failed: 1
    INFO certificate-manager Performing rollback of Machine SSL Cert

Environment

  • VMware vCenter Server 6.0.x
  • VMware vCenter Server 6.5.x
  • VMware vCenter Server 7.0.x

Cause

This issue can happen while trying to replace Machine SSL of vCenter Server using Custom Certificate with an unsupported Signature Algorithm RSASSA-PSS

Resolution

Additional Information

Refer to Doc Platform Services Controller Administration for more information on unsupported signature algorithms