TKGI 1.14.1 Installation fails during deployment over management console

owiegmann
Enthusiast
Enthusiast
0 3 2,843
Failed step 2/4: Deploying BOSH Director,: Error while deploying BOSH director: installation failed to trigger: request failed: unexpected response: HTTP/1.1 422 Unprocessable Entity Transfer-Encoding: chunked Cache-Control: private, no-store Connection: keep-alive Content-Security-Policy: script-src 'self'; img-src 'self' data:; style-src 'self' 'unsafe-inline'; object-src 'none'; Content-Type: application/json; charset=utf-8 Date: Tue, 26 Jul 2022 15:15:08 GMT Expires: Fri, 01 Jan 1990 00:00:00 GMT Pragma: no-cache Referrer-Policy: strict-origin-when-cross-origin Server: Ops Manager Strict-Transport-Security: max-age=63072000; includeSubDomains X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Permitted-Cross-Domain-Policies: none X-Request-Id: 3b817a57-aff1-40c4-82a2-694cb62ce264 X-Runtime: 1.990844 314 {"errors":["IaaS default: 'Error connecting to NSX IP: The NSX server's certificate is not signed with the provided NSX CA cert. Please provide the correct NSX CA cert', type: IaasConfigurationVerifier"],"deployment_errors":{"products":[{"identifier":"p-bosh-26245f372dd05d5246ae","complete":false,"network":{"assigned":true},"availability_zone":{"assigned":true},"stemcells":[{"assigned":true,"required_stemcell_version":"621.251","required_stemcell_os":"ubuntu-xenial"}],"properties":[],"resources":{"jobs":[]},"verifiers":[{"type":"IaasConfigurationVerifier","errors":["IaaS default: 'Error connecting to NSX IP: The NSX server's certificate is not signed with the provided NSX CA cert. Please provide the correct NSX CA cert', type: IaasConfigurationVerifier"],"ignorable":false}]}]}} 0
 
I replaced the certificates in NSX-T as described here:
 
Does somebody has an idea how the issue could be solved?
3 Comments
Rober1
Contributor
Contributor

Solution

Use SSH to log in to the Tanzu Kubernetes Grid Integrated Edition Management Console VM as root user.
Use the password that you specified when you deployed the OVA.
Run the following command to obtain the server logs:

journalctl -u pks-mgmt-server > server.log
If the logs do not provide the solution, delete the management console VM from vCenter Server and attempt to deploy it again. www.mygiftcardsite.com

simonemorellato
VMware Employee
VMware Employee

Hi,

It looks like you need to update NSX-T CA cert on the TKGI MC and apply configuration for updating CA to bosh tile.

7A9AD50B-6190-4539-8D08-4D0958E25DA7.jpeg

owiegmann
Enthusiast
Enthusiast

I could solve the issue by adding the certificate content to the networking configuration as adviced by @simonemorellato . 


TKGI Configuration, Step 2 NetworkingTKGI Configuration, Step 2 Networking