<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Auto Deploy 6.7 U1b - certificate issues at waiter.tgz in VMware vCenter™ Discussions</title>
    <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/2834965#M42387</link>
    <description>&lt;P&gt;Thanks to all.&lt;/P&gt;&lt;P&gt;We had the same problem with autodeploy stopping with "Fatal error: 15". Finding this page I checked rbd-cgi.log and vmcad-syslog.log ...&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;root@vc1 [ ~ ]# cat /var/log/vmware/rbd/rbd-cgi.log | grep -E "rror|ERROR"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:21:23.536 [6150]ERROR:vmcacertutil:Could not generate certificates for: 10.2.2.1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;out: b'Error: 5, VMCAGetSignedCertificatePrivate() failedError Code : 5\nMessage :UNKNOWN\n'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:21:23.553 [6150]ERROR:pluginmaster:exception:rbdplugins.sslcert.vmwWaiterTgz -- 0:b'Error: 5, VMCAGetSignedCertificatePrivate() failedError Code : 5\nMessage :UNKNOWN\n':b"Operation Failed: exception &amp;lt;class 'vmca.vmca_exception'&amp;gt; not a BaseException subclass"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Exception: 0:b'Error: 5, VMCAGetSignedCertificatePrivate() failedError Code : 5\nMessage :UNKNOWN\n':b"Operation Failed: exception &amp;lt;class 'vmca.vmca_exception'&amp;gt; not a BaseException subclass"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:21:23.554 [6150]WARNING:waitertgz:retrying waiter tgz because of rc: [None, None, None], except: [Exception('0:b\'Error: 5, VMCAGetSignedCertificatePrivate() failedError Code : 5\\nMessage :UNKNOWN\\n\':b"Operation Failed: exception &amp;lt;class \'vmca.vmca_exception\'&amp;gt; not a BaseException subclass"',)]&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;root@vc1 [ ~ ]# tail /var/log/vmware/vmcad/vmcad-syslog.log&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:34:52.765706+01:00 info vmcad t@140664742344338: VMCACheckAccessKrb: Authenticated user waiter-a67cf497-3462-48bb-868d-866c983aa484@vsphere.local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:34:52.770946+01:00 info vmcad t@140664742344338: Checking upn: cn=CAAdmins,cn=Builtin,dc=vsphere,dc=local against CA admin group: waiter-a67cf497-3462-48bb-868d-866c983aa484@vsphere.local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:34:52.771150+01:00 warning vmcad t@140664742344338: error code: 0x00000005&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:34:52.771329+01:00 warning vmcad t@140664742344338: error code: 0x00000005&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:34:52.771497+01:00 warning vmcad t@140664742344338: error code: 0x00000005&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Using dir-cli in vCenter shell I checked users in CAAdmins group and found out that two waiter accounts are there but the one from vmcad-syslog.log (waiter-a67cf497-3462-48bb-868d-866c983aa484) is missing.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;root@vc1 [ ~ ]# /usr/lib/vmware-vmafd/bin/dir-cli group list --name CAAdmins&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Enter password for administrator@vsphere.local:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cn=Administrator,cn=Users,dc=vsphere,dc=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cn=DCAdmins,cn=Builtin,dc=vsphere,dc=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cn=DCClients,cn=Builtin,dc=vsphere,dc=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CN=waiter 0af35be1-fc4b-427a-8181-1a25dbaa1270,cn=users,dc=vsphere,dc=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CN=waiter 5a882302-063f-4bb1-9eac-6cbd662d5130,cn=users,dc=vsphere,dc=local&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I looked for this particular user in other user groups (Users, Administrators ...) hoping I will find it somewhere but I did not. So I tried to create it and found out that it actually exists:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;root@vc1 [ ~ ]# /usr/lib/vmware-vmafd/bin/dir-cli user create --account waiter-a67cf497-3462-48bb-868d-866c983aa484 --first-name waiter --last-name a67cf497-3462-48bb-868d-866c983aa484 --user-password 'testpass'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Enter password for administrator@vsphere.local:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;dir-cli failed. Error 9706: Possible errors:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;LDAP error: Already exists&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Win Error: Operation failed with error ERROR_TOO_MANY_NAMES (68)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great, because I had no idea what password to give to the new user. Now I just had to add existing user to CAAdmins group:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;root@vc1 [ ~ ]# /usr/lib/vmware-vmafd/bin/dir-cli group modify --name CAAdmins --add waiter-a67cf497-3462-48bb-868d-866c983aa484&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adding user to CAAdmins group was successful and Autodeploy started working immediately.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Mar 2021 11:40:23 GMT</pubDate>
    <dc:creator>Ivanuci</dc:creator>
    <dc:date>2021-03-10T11:40:23Z</dc:date>
    <item>
      <title>Auto Deploy 6.7 U1b - certificate issues at waiter.tgz</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/445445#M3270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm developing auto-deploy and i've gotten to the point where a the ESXi installation begins, but stalls when trying to install waiter.tgz. I checked the /var/log/vmware/rbd/rbd-cgi.log file and found this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;beacon:Adding etc/vmware/autodeploy/waiternotify.json&lt;/P&gt;&lt;P&gt;cache_tables:cache request ....&lt;/P&gt;&lt;P&gt;sslutil:cert files are missing from &amp;lt;UID&amp;gt; (autodeployhost.contoso.com)&lt;/P&gt;&lt;P&gt;sslcert:Generating SSL cert for &amp;lt;UID&amp;gt; (autodeployhost.contoso.com)&lt;/P&gt;&lt;P&gt;ERROR:vmcacertutil:Could not generate certificates for: autodeployhost.contoso.com&lt;/P&gt;&lt;P&gt;rc:0&lt;/P&gt;&lt;P&gt;out: b'Error: 5, VMCASignedCertificatePrivate() failedError Code: 5\nMessage: UNKNOWN\n'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure what other info to provide to help determine the issue....any suggestions/guidance?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Jun 2019 17:18:37 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/445445#M3270</guid>
      <dc:creator>TimR26</dc:creator>
      <dc:date>2019-06-04T17:18:37Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Deploy 6.7 U1b - certificate issues at waiter.tgz</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/445446#M3271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Error 5 is access denied.. I am unsure if we are hitting any access denied here but i dont see&amp;nbsp; a reason for access denied in autodeploy...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried restarting the rbd service and then tried deploying the ESXi host?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you check the vpxd.log and the rbd.log &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Jun 2019 14:18:11 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/445446#M3271</guid>
      <dc:creator>msripada</dc:creator>
      <dc:date>2019-06-06T14:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Deploy 6.7 U1b - certificate issues at waiter.tgz</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/445447#M3272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;did you find a resolution for this issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Sep 2019 21:58:08 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/445447#M3272</guid>
      <dc:creator>matthewingram</dc:creator>
      <dc:date>2019-09-04T21:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Deploy 6.7 U1b - certificate issues at waiter.tgz</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/445448#M3273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same problem and see the same log entries in the &lt;SPAN style="font-family: courier new, courier;"&gt;/var/log/vmware/rbd/rbd-cgi.log&lt;/SPAN&gt; file. I was trying to re-deploy the host using auto deploy after upgrading VCSA from 6.0U3 to 6.7U2c, I even tried removing the host from the vCenter server's inventory but still the same problem, it gets stuck downloading &lt;SPAN style="font-family: courier new, courier;"&gt;waiter.tgz.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There seems to be a problem with the new certificate that tries to issue when host gets re-deployed. I've checked using the certool with the following command and I see there is still a certificate for that host that wasn't deleted when I removed it from the inventory:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;/usr/lib/vmware-vmca/bin/certool --enumcert --filter=all | less&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit: I've tried re-deploying the host after restarting the Auto Deploy waiter service, I also rebooted the VCSA once after removing the ESXi host from the inventory but it still gets stuck at the same step of the deployment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Oct 2019 14:53:46 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/445448#M3273</guid>
      <dc:creator>dbuenoparedes</dc:creator>
      <dc:date>2019-10-17T14:53:46Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Deploy 6.7 U1b - certificate issues at waiter.tgz</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/445449#M3274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This requires assigning necessary permissions to waiter user which has to be done by connecting to vmdird DB with LDAP browser (Jxplorer)&lt;/P&gt;&lt;P&gt;As the steps involved requires modifying vmdird DB, file a SR with GSS to get this sorted.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 Oct 2019 12:34:19 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/445449#M3274</guid>
      <dc:creator>Vijay2027</dc:creator>
      <dc:date>2019-10-20T12:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Deploy 6.7 U1b - certificate issues at waiter.tgz</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/445450#M3275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the reply &lt;B&gt;Vijay2027&lt;/B&gt;​, you nailed it, I ended up opening a ticket with VMware support. They checked these log files:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;/var/log/vmware/rbd/rbd-cgi.log (VCSA)&lt;/LI&gt;&lt;LI&gt;/var/log/vmware/vmcad/vmcad-syslog.log (PSC)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have an external PSC deployment in our environment, the key was in the following lines of the &lt;EM&gt;vmcad-syslog.log&lt;/EM&gt; file:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;2019-10-18T18:27:47.942203+00:00 warning vmcad&amp;nbsp; t@140271253645056: error code: 0x00000005&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;2019-10-18T18:27:47.942370+00:00 warning vmcad&amp;nbsp; t@140271253645056: error code: 0x00000005&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;2019-10-18T18:27:47.942537+00:00 warning vmcad&amp;nbsp; t@140271253645056: error code: 0x00000005&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;2019-10-18T18:28:08.373709+00:00 info vmcad&amp;nbsp; t@140271253645056: VMCACheckAccessKrb: Authenticated user waiter-d0cef9c5-5f40-4671-83f7-f611d19354cb@vsphere.local&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;2019-10-18T18:28:08.380445+00:00 info vmcad&amp;nbsp; t@140271253645056: Checking upn: cn=CAAdmins,cn=Builtin,dc=vsphere,dc=local against CA admin group: waiter-d0cef9c5-5f40-4671-83f7-f611d19354cb@vsphere.local&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;2019-10-18T18:28:08.380970+00:00 warning vmcad&amp;nbsp; t@140271253645056: error code: 0x00000005&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;2019-10-18T18:28:08.381299+00:00 warning vmcad&amp;nbsp; t@140271253645056: error code: 0x00000005&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;2019-10-18T18:28:08.381563+00:00 warning vmcad&amp;nbsp; t@140271253645056: error code: 0x00000005&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;2019-10-18T18:28:09.205803+00:00 info vmcad&amp;nbsp; t@140271253645056: VMCACheckAccessKrb: Authenticated user waiter-d0cef9c5-5f40-4671-83f7-f611d19354cb@vsphere.local&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-family: courier new, courier;"&gt;2019-10-18T18:28:09.210938+00:00 info vmcad&amp;nbsp; t@140271253645056: Checking upn: cn=CAAdmins,cn=Builtin,dc=vsphere,dc=local against CA admin group: waiter-d0cef9c5-5f40-4671-83f7-f611d19354cb@vsphere.local&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;What support ended up doing is connecting via LDAP (with JXplorer) to the PSC and creating that &lt;EM&gt;waiter-d0cef9c5-5f40-4671-83f7-f611d19354cb@vsphere.local &lt;/EM&gt;user that was missing from the CAAdmins group.After this user was created I was able to re-deploy the ESXi host without any issue. There were 2 other &lt;EM&gt;waiter&lt;/EM&gt; users with a different string of chars after them but for some reason Auto Deploy was looking for this one specifically but was missing from that group of users.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: tahoma, arial, helvetica, sans-serif;"&gt;I hope this helps.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Oct 2019 14:45:46 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/445450#M3275</guid>
      <dc:creator>dbuenoparedes</dc:creator>
      <dc:date>2019-10-22T14:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Deploy 6.7 U1b - certificate issues at waiter.tgz</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/445451#M3276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right. Sometimes we end up re-created the ID using dir-cli if the user doesn't exists.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Oct 2019 17:16:02 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/445451#M3276</guid>
      <dc:creator>Vijay2027</dc:creator>
      <dc:date>2019-10-22T17:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Deploy 6.7 U1b - certificate issues at waiter.tgz</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/2834965#M42387</link>
      <description>&lt;P&gt;Thanks to all.&lt;/P&gt;&lt;P&gt;We had the same problem with autodeploy stopping with "Fatal error: 15". Finding this page I checked rbd-cgi.log and vmcad-syslog.log ...&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;root@vc1 [ ~ ]# cat /var/log/vmware/rbd/rbd-cgi.log | grep -E "rror|ERROR"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:21:23.536 [6150]ERROR:vmcacertutil:Could not generate certificates for: 10.2.2.1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;out: b'Error: 5, VMCAGetSignedCertificatePrivate() failedError Code : 5\nMessage :UNKNOWN\n'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:21:23.553 [6150]ERROR:pluginmaster:exception:rbdplugins.sslcert.vmwWaiterTgz -- 0:b'Error: 5, VMCAGetSignedCertificatePrivate() failedError Code : 5\nMessage :UNKNOWN\n':b"Operation Failed: exception &amp;lt;class 'vmca.vmca_exception'&amp;gt; not a BaseException subclass"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Exception: 0:b'Error: 5, VMCAGetSignedCertificatePrivate() failedError Code : 5\nMessage :UNKNOWN\n':b"Operation Failed: exception &amp;lt;class 'vmca.vmca_exception'&amp;gt; not a BaseException subclass"&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:21:23.554 [6150]WARNING:waitertgz:retrying waiter tgz because of rc: [None, None, None], except: [Exception('0:b\'Error: 5, VMCAGetSignedCertificatePrivate() failedError Code : 5\\nMessage :UNKNOWN\\n\':b"Operation Failed: exception &amp;lt;class \'vmca.vmca_exception\'&amp;gt; not a BaseException subclass"',)]&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;root@vc1 [ ~ ]# tail /var/log/vmware/vmcad/vmcad-syslog.log&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:34:52.765706+01:00 info vmcad t@140664742344338: VMCACheckAccessKrb: Authenticated user waiter-a67cf497-3462-48bb-868d-866c983aa484@vsphere.local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:34:52.770946+01:00 info vmcad t@140664742344338: Checking upn: cn=CAAdmins,cn=Builtin,dc=vsphere,dc=local against CA admin group: waiter-a67cf497-3462-48bb-868d-866c983aa484@vsphere.local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:34:52.771150+01:00 warning vmcad t@140664742344338: error code: 0x00000005&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:34:52.771329+01:00 warning vmcad t@140664742344338: error code: 0x00000005&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;2021-03-03T09:34:52.771497+01:00 warning vmcad t@140664742344338: error code: 0x00000005&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Using dir-cli in vCenter shell I checked users in CAAdmins group and found out that two waiter accounts are there but the one from vmcad-syslog.log (waiter-a67cf497-3462-48bb-868d-866c983aa484) is missing.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;root@vc1 [ ~ ]# /usr/lib/vmware-vmafd/bin/dir-cli group list --name CAAdmins&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Enter password for administrator@vsphere.local:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cn=Administrator,cn=Users,dc=vsphere,dc=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cn=DCAdmins,cn=Builtin,dc=vsphere,dc=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;cn=DCClients,cn=Builtin,dc=vsphere,dc=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CN=waiter 0af35be1-fc4b-427a-8181-1a25dbaa1270,cn=users,dc=vsphere,dc=local&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;CN=waiter 5a882302-063f-4bb1-9eac-6cbd662d5130,cn=users,dc=vsphere,dc=local&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I looked for this particular user in other user groups (Users, Administrators ...) hoping I will find it somewhere but I did not. So I tried to create it and found out that it actually exists:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;root@vc1 [ ~ ]# /usr/lib/vmware-vmafd/bin/dir-cli user create --account waiter-a67cf497-3462-48bb-868d-866c983aa484 --first-name waiter --last-name a67cf497-3462-48bb-868d-866c983aa484 --user-password 'testpass'&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Enter password for administrator@vsphere.local:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;dir-cli failed. Error 9706: Possible errors:&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;LDAP error: Already exists&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Win Error: Operation failed with error ERROR_TOO_MANY_NAMES (68)&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Great, because I had no idea what password to give to the new user. Now I just had to add existing user to CAAdmins group:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier"&gt;root@vc1 [ ~ ]# /usr/lib/vmware-vmafd/bin/dir-cli group modify --name CAAdmins --add waiter-a67cf497-3462-48bb-868d-866c983aa484&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adding user to CAAdmins group was successful and Autodeploy started working immediately.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2021 11:40:23 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Auto-Deploy-6-7-U1b-certificate-issues-at-waiter-tgz/m-p/2834965#M42387</guid>
      <dc:creator>Ivanuci</dc:creator>
      <dc:date>2021-03-10T11:40:23Z</dc:date>
    </item>
  </channel>
</rss>

