VMware Cloud Community
LaurenMalhoit
Enthusiast
Enthusiast

Trying to add vCenter - unable to get vCenter server certificate chain

I'm trying to add another vCenter server in vCOPS.  I get the error:  unable to get vCenter server certificate chain. 

This is vCenter 5.1, vCOPS 5.8.

Any thoughts?

6 Replies
jddias
VMware Employee
VMware Employee

Sounds like maybe an expired certificate, can you confirm?

Visit my blog for vCloud Management tips and tricks - http://www.storagegumbo.com
0 Kudos
gradinka
VMware Employee
VMware Employee

...or weak certificate?

you need 2048bit public key, local SSH_CIPHERS="aes256-ctr,aes128-ctr"

0 Kudos
mark_j
Virtuoso
Virtuoso

I've seen an error for an expired SSL cert on vCenter, and what you're seeing isn't it.

I'm going to assume you've already checked for ssl expiration and the help of the cert+chain as per the previous recommendations.

Are you using SSL cert signed by a 3rd party CA? (your company CA, or perhaps something like GoDaddy). If so, you'll need to add the CAs on the chain in to the truststore even if the chain (even when the chain is built properly sometimes). See the following KB:

VMware KB: When attempting to access VMware vCenter Operations Manager 5.x, an error is displayed: N...

FYI, you also add the server certs to the truststore in the same fashion for LDAP SSL hosts in the Custom UI.

If you find this or any other answer useful please mark the answer as correct or helpful.
0 Kudos
AstraMonti
Enthusiast
Enthusiast

Did you find out anything about it? I am experiencing the same issue myself.    

0 Kudos
gradinka
VMware Employee
VMware Employee

are you "all clear" on the options mentioned above?

0 Kudos
AstraMonti
Enthusiast
Enthusiast

I am using vcenters' self signed certificate on that installation, so unless I am missing something I would say yes, all clear.   

Edit: Sorry my fault, followed that kb and fixed it: VMware KB: When attempting to access VMware vCenter Operations Manager 5.x, an error is displayed: N...