<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Certificate alert after upgrade to VCSA 7.0 in VMware vCenter™ Discussions</title>
    <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2841458#M42688</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;a customer is gettng a altert that a certificate will expire soon.&lt;BR /&gt;&lt;BR /&gt;During upgrade from 6.7 to 7.0 we renew all certificates and we executed the checksts.py script.&lt;/P&gt;&lt;P&gt;The STS has 2 certificates, the leaf expires in 2 years and the root in 8 years.&lt;BR /&gt;&lt;BR /&gt;So we checked all certificate stores and identified this one:&amp;nbsp;STS_INTERNAL_SSL_CERT&lt;BR /&gt;&lt;BR /&gt;This certificate will expire in a few days.&lt;BR /&gt;&lt;BR /&gt;Is this certificate still needed? Can i delete that certificate store? Because on a fresh installed VCSA 7.0 i havn't such a store.&lt;BR /&gt;&lt;BR /&gt;Has someone here seen the same?&lt;BR /&gt;&lt;BR /&gt;Kind regards&lt;BR /&gt;Stefan&lt;/P&gt;</description>
    <pubDate>Tue, 13 Apr 2021 07:24:09 GMT</pubDate>
    <dc:creator>Raudi</dc:creator>
    <dc:date>2021-04-13T07:24:09Z</dc:date>
    <item>
      <title>Certificate alert after upgrade to VCSA 7.0</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2841458#M42688</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;a customer is gettng a altert that a certificate will expire soon.&lt;BR /&gt;&lt;BR /&gt;During upgrade from 6.7 to 7.0 we renew all certificates and we executed the checksts.py script.&lt;/P&gt;&lt;P&gt;The STS has 2 certificates, the leaf expires in 2 years and the root in 8 years.&lt;BR /&gt;&lt;BR /&gt;So we checked all certificate stores and identified this one:&amp;nbsp;STS_INTERNAL_SSL_CERT&lt;BR /&gt;&lt;BR /&gt;This certificate will expire in a few days.&lt;BR /&gt;&lt;BR /&gt;Is this certificate still needed? Can i delete that certificate store? Because on a fresh installed VCSA 7.0 i havn't such a store.&lt;BR /&gt;&lt;BR /&gt;Has someone here seen the same?&lt;BR /&gt;&lt;BR /&gt;Kind regards&lt;BR /&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 07:24:09 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2841458#M42688</guid>
      <dc:creator>Raudi</dc:creator>
      <dc:date>2021-04-13T07:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate alert after upgrade to VCSA 7.0</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2841625#M42695</link>
      <description>&lt;P&gt;Yes it is from the legacy SSO (port 7444), I am guessing your vCenter was upgraded all the way from 5.5 - It does not serve any purposes in 7.0.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would suggest you to just backup the cert and key just in case and delete the store with the cert. You can do all that by executing following&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/usr/lib/vmware-vmafd/bin/vecs-cli entry getcert --store STS_INTERNAL_SSL_CERT --alias __MACHINE_CERT --output /var/tmp/STS_INTERNAL.crt&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/usr/lib/vmware-vmafd/bin/vecs-cli entry getkey --store STS_INTERNAL_SSL_CERT --alias __MACHINE_CERT --output&amp;nbsp;/var/tmp/STS_INTERNAL.key&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Finally delete the store using:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/usr/lib/vmware-vmafd/bin/vecs-cli store delete --name&amp;nbsp;STS_INTERNAL_SSL_CERT&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 01:55:49 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2841625#M42695</guid>
      <dc:creator>Sanooj_aj</dc:creator>
      <dc:date>2021-04-14T01:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate alert after upgrade to VCSA 7.0</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2841799#M42703</link>
      <description>&lt;P&gt;This sounds perfect, i expected something that kind, but wasn't shure if i can delete it.&lt;/P&gt;&lt;P&gt;Even the support can't. He want's to do some research...&lt;/P&gt;&lt;P&gt;We will test it next friday, i will write the result.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 15:45:52 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2841799#M42703</guid>
      <dc:creator>Raudi</dc:creator>
      <dc:date>2021-04-14T15:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate alert after upgrade to VCSA 7.0</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2842163#M42716</link>
      <description>&lt;P&gt;O.k. bad news, the store seems to be still in use, after deleting the store we made a reboot and the service&amp;nbsp;&lt;SPAN&gt;vmware-stsd don't came up.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So i used this command to recreate the store:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;/usr/lib/vmware-vmafd/bin/vecs-cli store create --name STS_INTERNAL_SSL_CERT&lt;/P&gt;&lt;P&gt;and then i followed this KB:&amp;nbsp;&lt;A href="https://kb.vmware.com/s/article/76144" target="_blank"&gt;https://kb.vmware.com/s/article/76144&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;usr/lib/vmware-vmafd/bin/vecs-cli entry getcert --store MACHINE_SSL_CERT --alias __MACHINE_CERT --output /var/tmp/machine_ssl.crt&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;/usr/lib/vmware-vmafd/bin/vecs-cli entry getkey --store MACHINE_SSL_CERT --alias __MACHINE_CERT --output /var/tmp/machine_ssl.key&lt;BR /&gt;/usr/lib/vmware-vmafd/bin/vecs-cli entry create --store STS_INTERNAL_SSL_CERT --alias __MACHINE_CERT --cert /var/tmp/machine_ssl.crt --key /var/tmp/machine_ssl.key&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now i have again a valid certificate, which do not expire in a few days, in the store and i was able to start the service.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have collected a support bundle and send it to the support. This can't be correct...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Apr 2021 08:27:22 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2842163#M42716</guid>
      <dc:creator>Raudi</dc:creator>
      <dc:date>2021-04-16T08:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate alert after upgrade to VCSA 7.0</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2842311#M42722</link>
      <description>&lt;P&gt;That means there could be legacy sts endpoints exists in the service registrations that will need to be cleaned up so that the store is not being used.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Apr 2021 19:41:45 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2842311#M42722</guid>
      <dc:creator>Sanooj_aj</dc:creator>
      <dc:date>2021-04-16T19:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate alert after upgrade to VCSA 7.0</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2842707#M42740</link>
      <description>&lt;P&gt;What is the SR number ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Apr 2021 03:50:50 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2842707#M42740</guid>
      <dc:creator>Ajay1988</dc:creator>
      <dc:date>2021-04-20T03:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate alert after upgrade to VCSA 7.0</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2842736#M42742</link>
      <description>&lt;P&gt;&lt;A href="https://kb.vmware.com/s/article/80469" target="_blank" rel="noopener"&gt;https://kb.vmware.com/s/article/80469&lt;/A&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Run through this and get output for&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;python lsdoctor.py -l&lt;/STRONG&gt; and&amp;nbsp; if there is old 5.5 registrations ; then use&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;python lsdoctor.py -s&lt;/STRONG&gt; to fix old registrations .&lt;/P&gt;&lt;P&gt;Modify the below file :-&lt;BR /&gt;&lt;STRONG&gt;/usr/lib/vmware-sso/vmware-sts/conf/server.xml&lt;/STRONG&gt; :&amp;nbsp;&lt;SPAN&gt;Modify the 2 entries in the server.xml which has "&lt;STRONG&gt;STS_INTERNAL_SSL_CERT&lt;/STRONG&gt;" to "&lt;STRONG&gt;MACHINE_SSL_CERT&lt;/STRONG&gt;" .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;And then delete the&amp;nbsp; &lt;SPAN&gt;&lt;STRONG&gt;STS_INTERNAL_SSL_CERT&amp;nbsp; &amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;store and restart services.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Follow&amp;nbsp; &amp;nbsp;&lt;A href="https://virtual-power.in/f/21-stsd-crash-opening-store-stsinternalsslcert-failed" target="_self"&gt;https://virtual-power.in/f/21-stsd-crash-opening-store-stsinternalsslcert-failed&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Apr 2021 13:49:56 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2842736#M42742</guid>
      <dc:creator>Ajay1988</dc:creator>
      <dc:date>2021-04-20T13:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate alert after upgrade to VCSA 7.0</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2842873#M42748</link>
      <description>&lt;P&gt;This sounds&amp;nbsp;promising, we will test and report.&amp;nbsp;&lt;img class="lia-deferred-image lia-image-emoji" src="https://communities.vmware.com/html/@677206E94727C39F3BB2721E5A55F2C1/emoticons/1f609.png" alt=":winking_face:" title=":winking_face:" /&gt;&lt;/P&gt;&lt;P&gt;The SR: 21212630304&lt;/P&gt;&lt;P&gt;Today i had a phonecall with the support and he told me to use the fixsts script to repair this, doesn't help...&lt;/P&gt;&lt;P&gt;Kind regards&lt;BR /&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Tue, 20 Apr 2021 16:02:41 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2842873#M42748</guid>
      <dc:creator>Raudi</dc:creator>
      <dc:date>2021-04-20T16:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate alert after upgrade to VCSA 7.0</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2842993#M42757</link>
      <description>&lt;P&gt;Problem solved, we need only to modify the file&amp;nbsp;/usr/lib/vmware-sso/vmware-sts/conf/server.xml and replace the 2 entries.&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 08:38:25 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Certificate-alert-after-upgrade-to-VCSA-7-0/m-p/2842993#M42757</guid>
      <dc:creator>Raudi</dc:creator>
      <dc:date>2021-04-21T08:38:25Z</dc:date>
    </item>
  </channel>
</rss>

