VMware Cloud Community
KKvss
Enthusiast
Enthusiast

vLCM - HPe HSM - Fetching of online depot URL failed

Hello Team VMware,

today, I want to try the new vLCM in combination with HPe iLO Amplifier to firmware patching my ESXi hosts.

I successfully installed the HPe iLO Amplifier appliance and let it communicate with the vCenter.

I also uploaded the 3 latest HPe SPP firmware into the appliance but I can´t use it in the vCenter.

When I press "Add" for the Online Software Depot I get the following error:

Fetching of online depot URL failed. Depot URL not found in the SPP details.

Is somebody aware about that or got the HPe iLO Amplifier with VUM to fly?

Fetching Error.JPG

vCenter 7: 16386335
ESXi 7: 16324942
Amplifier: 1.70

I really appreciate your help in advance.

Greetings

KKvss

49 Replies
vjrk83
Enthusiast
Enthusiast

ok. ILO4( on Gen9's) are not capable of using SUT ? Is there any document thats available to use the ilo amp web interface for Gen9's to update the firmwares ? 

Reply
0 Kudos
vjrk83
Enthusiast
Enthusiast

Do you mean the ILO firmware version or the ILo4 which doesnt support SUT ? 

Reply
0 Kudos
MrJazze
Enthusiast
Enthusiast

For those wanting to keep with the practice for resolving DNS name, I first updated my ILOAP with VM's Host name, Domain Name and DNS Search.

 

Configuration and Settings > Network Settings > General Settings > modified the 3 fields (default hostname "local") > clicked Save button > clicked Reboot button.

Then > Configuration and Settings > Security Settings > SSL Certificates > clicked Generate Self Signed Certificate. This will generate the cert with FQDN and IP Address.

VCSA web interface > Access > clicked Edit button > ticked Enable slider > clicked OK button.

SSH session into VCSA > type "shell" > enter the following lines, replacing fqdn-of-your-ILOAP

 

[ ~ ]#  true | openssl s_client -connect fqdn-of-your-ILOAP:443 -showcerts > /tmp/iloap-cert.crt

 

[ ~ ]#  cat /tmp/iloap-cert.crt >> /usr/lib/python3.7/site-packages/certifi/cacert.pem

 

[ ~ ]#  cat /tmp/iloap-cert.crt >> /etc/pki/tls/certs/ca-bundle.crt

 

Now, go back to vSphere web client and refresh certificate page, you will see the iLO Amplifier Pack root certificate is imported.

 

 

Reply
0 Kudos
visd
Contributor
Contributor

This worked for me, while configuring for ov4vc [oneview for vcenter]... Thanks!! 🙂

Reply
0 Kudos
Carl_Miner
Contributor
Contributor

Hi,

before one week I had faced same issue on my location , I opened a HPe ticket but still no get any solution.

official site  

Reply
0 Kudos
Totoro-Totoro
Contributor
Contributor

Good call.  In my case I also had to rename the iLO Amp appliance and generate a new certificate too.

Reply
0 Kudos
lexajum
Contributor
Contributor

Although i added the certificate, I was getting the "Some error occurred while online depot registration"

To solve this problem i modified /etc/sysconfig/proxy file in vcenter.

i excluded the iloamp ip address like;

# Example: NO_PROXY="www.me.de, do.main, localhost"
NO_PROXY="localhost, 127.0.0.1, <ipaddressofiloamp>"

Reply
0 Kudos
stupots
Contributor
Contributor

I hope you guys don't mind me posting this here, it seems a good way to get the attention of ILO Amplifier users... are you aware that there is a major (9.8 CVE score) security vulnerability in 1.95 and most other versions and that version 2.0 is now out? I've posted about it (and the problems I'm having adding a vCenter server) here:
https://communities.vmware.com/t5/Update-Manager-Discussions/ILO-Amplifier-2-0-cannot-add-vCenter/m-...

Thanks

Stu

 

Reply
0 Kudos
bfrericks21
Contributor
Contributor

I tried everything in this post to no avail.  I have a simple setup, Single vCenter iLO Amp, successfully registered HSM with vCenter but couldn't import any of the SPPs or VUPs, same error as everyone else.  I happened upon this VMware blog and this fixed my problem.  Hope this helps someone else from spending a half-day trying to figure it out....

vSphere Lifecycle Manager (vLCM) on HPE | Virtual Blocks (vmware.com)

 

Login as root on the vCenter and enter the following command:

true | openssl s_client -connect :443 -showcerts >/tmp/iloamp-cert.crt

You should see something like

 

1
2
3
4
5
6
depth=0 C = US, O = Organization, CN = localhost, ST = State, L = Locality, OU = OrganizationalUnit
verify error:num=18:self signed certificate
verify return:1
depth=0 C = US, O = Organization, CN = localhost, ST = State, L = Locality, OU = OrganizationalUnit
verify return:1
DONE

 

Enter the following to add the certificate to VC’s list of known and trusted certificates:

 

1
/usr/lib/vmware-vmafd/bin/dir-cli trustedcert publish --cert /tmp/iloamp-cert.crt

 

You should be prompted for your password and see "Certificate published successfully"

Reply
0 Kudos
JERRY654
Contributor
Contributor

When encountering a "Fetching of online depot URL failed" error in vLCM (VMware Lifecycle Manager) with HPe HSM (Hewlett Packard Enterprise Hardware Support Manager), it's crucial to address potential causes to ensure seamless updates and maintenance of your infrastructure.

Reply
0 Kudos