VMware Cloud Community
pintu27
Contributor
Contributor

I replaced the ESX default SSL certificate with mine & now i cant add it Virtual Center

Hey,

I have added new SSL certificates to ESX servers & too Virtual Center from my MS Enterprise CA. Individually I can connect to VC and ESX server bu whenever I am adding the ESX to VC it is able to install Virtual Center Agent files.

Then I replaced the ESX SSL certificates with default one now I can add it VC.

Can anybody tell me why my certificates are not working when it is installed on ESX server? In real senario it works or not!!

Any clue regarding this??

regards,

Briz

Reply
0 Kudos
8 Replies
palberto
Contributor
Contributor

Briz, have you come up with anything on this? I haven't my self, but I am having the same problem as you. I have searched everywhere with no luck. Any insight?

regards,

Peter

Reply
0 Kudos
admin
Immortal
Immortal

Take a look at the following VMware Knowledge Base article

http://kb.vmware.com/kb/1003070

Reply
0 Kudos
palberto
Contributor
Contributor

Yea, I tried that didn't work out. have you had any experience creating the .pfx files, the concatenation of the .crt and .key? I think thats where my issue lies. thanks

Peter

Reply
0 Kudos
pintu27
Contributor
Contributor

hi,

Sorry buddy. After that I didnt get time to try...

I was just busy in my capacity planning...

may be next week I will be kicking off my test lab again to validate my design..

then I will take a look on this problem again.. let me me you have come across with any solution...

Otherwise will log a call with support center!!

Regards,

Brajesh

Reply
0 Kudos
mittim12
Immortal
Immortal

I was having the same problem after I replaced my SSL cert. I found the following error in the vpxa log Failed: unrecognized file format: /etc/vmware/ssl/rui.crt. Everytime I tried to add the host to VC I receved the previous error and the task would fail at 80%

I ended up opening a ticket with VMware support. Support noticed my cert was lacking the certificate text at the begining of the crt file. In order to fix this I had to run the following command

openssl x509 -text -in rui.crt > rui.new

Once I ran this I backed up the old rui.crt and rename rui.new ro rui.crt. A simple restart of the vmare-mgmt service then corrected my problem. I have attached the document they sent me to show what the bad certificate looks like and what a good certificate looks like.

If you found this or any other post helpful please consider the use of the Helpfull/Correct buttons to award points

Reply
0 Kudos
palberto
Contributor
Contributor

Wow, thats great. Now on the windows side have you had any experience creating the .pfx file from the key and crt? I have had no success with that. any pointers?

Peter

Reply
0 Kudos
pintu27
Contributor
Contributor

Can you publish a complete guide for this activity?

Really it will be helpfull for everybody. I will give you full mark Smiley Happy

Reply
0 Kudos
mittim12
Immortal
Immortal

I don't have a VMware guide but this thread, , provides and excellent reference and actually contains a step by step guide that someone created for requesting a cert and implmenting it for Virtual Center. I highly advise reading this thread.

Reply
0 Kudos