Hi Al
I have a very strange issue in that the VMware Truesso enrolment service is unable to connect to the issuing CA service even though they are on the same server instance. I am trying to setup the enrolment service to talk to a Horizon cloud platform; however the enrolment service isn't able to talk to the certificate service even though it has specific permissions to do so in the CA server configuration. From digging through all the logs the only thing of any relevance that appears within: "C:\ProgramData\VMware\VDM\logs"
2019-08-18T02:38:47.859-07:00 TRACE (0A58-1AEC) <MessageFrameWorkDispatch> [wsnm_certenroll] EnrollmentServices::GenerateAndSignPKCS10CMC(): Enter - Generate And Sign PKCS10CMC
2019-08-18T02:38:47.875-07:00 TRACE (0A58-1AEC) <MessageFrameWorkDispatch> [wsnm_certenroll] EnrollmentServices::GenerateAndSignPKCS10CMC(): Exit
2019-08-18T02:38:47.875-07:00 TRACE (0A58-1AEC) <MessageFrameWorkDispatch> [wsnm_certenroll] CertSrvPool::SubmitToCaQueue(): Enter - Submit Queue
2019-08-18T02:38:47.875-07:00 DEBUG (0A58-1AEC) <MessageFrameWorkDispatch> [wsnm_certenroll] CertSrvPool::SubmitToCaQueue(): No Connected CA - wait for one to connect Id=1
2019-08-18T02:38:48.890-07:00 DEBUG (0A58-1AEC) <MessageFrameWorkDispatch> [wsnm_certenroll] CertSrvPool::SubmitToCaQueue(): No Connected CA - wait for one to connect Id=1
2019-08-18T02:38:49.906-07:00 DEBUG (0A58-1AEC) <MessageFrameWorkDispatch> [wsnm_certenroll] CertSrvPool::SubmitToCaQueue(): No Connected CA - wait for one to connect Id=1
2019-08-18T02:38:50.922-07:00 TRACE (0A58-1AEC) <MessageFrameWorkDispatch> [wsnm_certenroll] CertSrvPool::SubmitToCaQueue(): Completed request id=1 - FAILED - elapsed=3047ms
2019-08-18T02:38:50.922-07:00 TRACE (0A58-1AEC) <MessageFrameWorkDispatch> [wsnm_certenroll] CertSrvPool::SubmitToCaQueue(): Exit
2019-08-18T02:38:50.922-07:00 ERROR (0A58-1AEC) <MessageFrameWorkDispatch> [wsnm_certenroll] EnrollmentServices::SubmitRequest(): Failed to locate a connected CA - ErrorCode = 2147944650 (0x00000000800708CA)
2019-08-18T02:38:50.922-07:00 TRACE (0A58-1AEC) <MessageFrameWorkDispatch> [wsnm_certenroll] EnrollmentServices::SubmitRequest(): Exit
2019-08-18T02:38:50.922-07:00 TRACE (0A58-1AEC) <MessageFrameWorkDispatch> [wsnm_certenroll] EnrollmentConnection::SubmitRequest(): Exit
2019-08-18T02:38:50.922-07:00 ERROR (0A58-1AEC) <MessageFrameWorkDispatch> [wsnm_certenroll] CertEnrollService::CertEnrollOperation::SubmitRequestHandler(): Failed to locate a connected CA - ErrorCode = 2147944650 (0x00000000800708CA)
2019-08-18T02:38:50.922-07:00 TRACE (0A58-1AEC) <MessageFrameWorkDispatch> [wsnm_certenroll] CertEnrollService::CertEnrollOperation::SubmitRequestHandler(): Exit
Any ideas would be greatly appreciated as I need to stand this service up urgently; I have also been in contact with VMware support however they don't seem to understand why this isn't working either?
I've been battling the same issue but I think I have it fixed now. I had to import the Connection Server certificate WITH the private key into the "VMware Horizon View Enrollment Server Trusted Roots" store on the Enrollment Server.
If you have anything to add please let me know, I'm continuing to test.
I am facing the same problem in the Azure deployment
SubmitRequest Failed
Response ErrorCode = "-2147022646"
ErrorText = "Failed to locate a connected CA"
FailureReason = "SubmitFailureMayRetry"
Hello,
any update regarding your issue ?
ame here, and export HZCS Cert with Private key, but same result ...
SubCA is on same server than HZES ......
Hi, did you export the correct Horizon Connection server certificate? It's not the "vdm" certificate you need, but the "vdm.ec" certificate.