VMware Cloud Community
ashaduzzaman
Contributor
Contributor

VCF bringup failed with error "Failed to Import VMCA root certificate"

While bringup vcf it failed to import certificate, just after vcenter install through vcf.

Please help i m stuck here.

 

  • Kiron
0 Kudos
9 Replies
shank89
Expert
Expert

Hi,

 

To clarify, is this the bringup of the management domain or a workload domain?

Have you used any uppercase characters in naming anywhere?

Have you checked the domainmanager.log ?  Are you able to post it?

Cheers

Shashank Mohan

VCIX-NV 2022 | VCP-DCV2019 | CCNP Specialist

https://lab2prod.com.au
LinkedIn https://www.linkedin.com/in/shankmohan/
Twitter @ShankMohan
Author of NSX-T Logical Routing: https://link.springer.com/book/10.1007/978-1-4842-7458-3
ashaduzzaman
Contributor
Contributor

Hi Mohan,

The bringup is for Management domain, and I don't use any uppercase letter.

from where i get domanimanager.log

Regards

Kiron

0 Kudos
shank89
Expert
Expert

you'll need the vcf-bringup-debug.log from the cloud builder appliance. 

https://docs.vmware.com/en/VMware-Cloud-Foundation/4.0/com.vmware.vcf.ovdeploy.doc_40/GUID-BD989650-...

Shashank Mohan

VCIX-NV 2022 | VCP-DCV2019 | CCNP Specialist

https://lab2prod.com.au
LinkedIn https://www.linkedin.com/in/shankmohan/
Twitter @ShankMohan
Author of NSX-T Logical Routing: https://link.springer.com/book/10.1007/978-1-4842-7458-3
0 Kudos
ashaduzzaman
Contributor
Contributor

Hi Mohan,

 

Attached is debug file.

 

Kiron

0 Kudos
shank89
Expert
Expert

This is from your log file

"Caused by: com.vmware.evo.sddc.common.core.error.InvalidInputException: Invalid parameter: IP sfo01-m01-esx01.sed.com cannot be connected"

Can you please ensure this is working?

Shashank Mohan

VCIX-NV 2022 | VCP-DCV2019 | CCNP Specialist

https://lab2prod.com.au
LinkedIn https://www.linkedin.com/in/shankmohan/
Twitter @ShankMohan
Author of NSX-T Logical Routing: https://link.springer.com/book/10.1007/978-1-4842-7458-3
0 Kudos
ashaduzzaman
Contributor
Contributor

Hi Mohan,

sfo01-m01-esx01.sed.com is alive, I can SSH from Cloud builder Machine. Attached is screenshot. 

I have reinstall again from scratch, but stuck in same field, attached is todays Debug log.

Please help me. I cant understand what is the issue, should I need to do anything manually to Import Certificate?

It is importing certificate from where to where?

My another question:

1. If customer purchase VCF, and if we deploy all component (vCenter, NSX-T, SDDC manager, vRealize etc) manually without Cloud builder, will it be any issue, or Can I do that?

ashaduzzaman_0-1618988881240.png

 

Regards

ashaduzzaman

0 Kudos
toffaha1
Enthusiast
Enthusiast

Hi @ashaduzzaman 

try to change the default shell of vCSA to bash shell then retry from Cloud Builder UI

https://kb.vmware.com/s/article/2100508

BR,

Muhammad Toffaha

Technical Consultant-PSO

Best Regards,
Muhammad Toffaha
Technical Consultant
0 Kudos
ashaduzzaman
Contributor
Contributor

Hi Muhammad,

vCSA have Bash enabled, no luck with this, same error message.

ashaduzzaman_0-1619024023691.png

 

Regards

ashaduzzaman

0 Kudos
shank89
Expert
Expert

Are you ignoring the thumbprint in the spreadsheet?

It's attempting to import the certificates as part of attaching the hosts to vcenter.  

 

I wouldn't manually build.  Can you try adding the host to vcenter see if it works manually and then remove and retry the workflow?

 

 

Shashank Mohan

VCIX-NV 2022 | VCP-DCV2019 | CCNP Specialist

https://lab2prod.com.au
LinkedIn https://www.linkedin.com/in/shankmohan/
Twitter @ShankMohan
Author of NSX-T Logical Routing: https://link.springer.com/book/10.1007/978-1-4842-7458-3
0 Kudos