VMware Cloud Community
JohannesBernhar
Contributor
Contributor
Jump to solution

ESXi Hosts are disconnected from vCenter (5.5)

Hi all,

we have a little problem with our vCenter.

We have two host which are connected to the vCenter, unfortunately they are shown as disconnected.

It seems that the problem are the SSL certs on the ESXi hosts which aren't valid anymore.

When I replace the old certificates with new ones I have to restart the ESXi Host, am I right?

If so thats the Problem.

We don't use any automatic vMotion and as long as the hosts are not connected to the vCenter I can't move them manually, right?

Is it possible to connect the hosts to the vCenter without using SSL?

Sorry for my bad english, I am not a nativ speaker.

Cheers,

Johannes

1 Solution

Accepted Solutions
vHaridas
Expert
Expert
Jump to solution

You need to replace SSL Certificates of ESXi Host.

Refer below Docs for ESXi Cert replacement.

ttp://www.bluebox-web.com/2013/04/18/replace-esxi-certificate/

vSphere 5.5 Documentation Center

I had to regenerate SSL certificates for ESXi 5.5, which I did without any downtime to VMs.

Certificate replacement process may change based on esxi version.

as per Doc vSphere 6.0 Documentation Center ESXi6 Host needs to be restarted to replace certs.

Anyway, in Current disconnected state you can try to regenerate self signed SSL certs, restart management agents and try to reconnect host in vCenter.

Thanks,

Haridas

Please consider awarding points for "Correct" or "Helpful" replies. Thanks....!!! https://vprhlabs.blogspot.in/

View solution in original post

5 Replies
a_p_
Leadership
Leadership
Jump to solution

Welcome to the Community,

First of all it is important to understand the reason why the hosts are disconnected.

Were they connected before, and working properly?

What happens if you try to connect the hosts from the vCenter Server GUI?

Did you install updates on the hosts (remember that ESXi 5.5 U3b requires vCenter Server 55 U3b or later)?

Did you already try to restart Management Agents on the hosts?

André

0 Kudos
JohannesBernhar
Contributor
Contributor
Jump to solution

Hi André,

thank you for your help.

The hosts were connected befor and worked without any Problem, no Updates were installed on them.

The SSL certificate has run out on April 16th and I see log-messages like this:

2016-04-20T16:46:03.546+02:00 [01392 error 'HttpConnectionPool-000001'] [ConnectComplete] Connect failed to <cs p:00000000075dadd0, TCP:*********:443>; cnx: (null), error: class Vmacore::Ssl::SSLVerifyException(SSL Exception: Verification parameters:

--> PeerThumbprint: DA:78:6B:87:5C:56:82:8F:8F:72:5A:37:48:04:30:69:40:08:E0:FC

--> ExpectedThumbprint:

--> ExpectedPeerName: *******

--> The remote host certificate has these problems:

-->

--> * A certificate in the host's chain is not time-valid.

-->

--> * The certificate is not time-valid.

-->

--> * unable to get local issuer certificate)

so I guess this is the problem, please tell me if I am wrong.

Didn't take any actions cause I  didn't want to risk shutting down VMs by accident.

Can I restart the Management Agents on the host without any impact to the running VMs?

Johannes

0 Kudos
a_p_
Leadership
Leadership
Jump to solution

Are you using your own certificates? I'm asking because "The default SSL certificates of vCenter Server are valid for 10 years and that of ESX/ESXi 4.x/5.x are valid for a period of 11.5 years.".

I never had to deal with expired certificates on ESXi hosts, so I can't currently tell you for sure whether there's a workaround in order to avoid a host reboot after replacing the certificate.

Restarting the Management Agents shouldn't cause an issues with the VMs with default vSphere configurations. The only exception that I'm aware of is for stand alone hosts with Autostart/Autoshutdown configured VMs, where the VMs may shutdown/reboot.

Anyway in case of expired certificates I doubt that restarting the Management Agents will help.

Sorry that I cannot help you much with this issue.

André

0 Kudos
vHaridas
Expert
Expert
Jump to solution

You need to replace SSL Certificates of ESXi Host.

Refer below Docs for ESXi Cert replacement.

ttp://www.bluebox-web.com/2013/04/18/replace-esxi-certificate/

vSphere 5.5 Documentation Center

I had to regenerate SSL certificates for ESXi 5.5, which I did without any downtime to VMs.

Certificate replacement process may change based on esxi version.

as per Doc vSphere 6.0 Documentation Center ESXi6 Host needs to be restarted to replace certs.

Anyway, in Current disconnected state you can try to regenerate self signed SSL certs, restart management agents and try to reconnect host in vCenter.

Thanks,

Haridas

Please consider awarding points for "Correct" or "Helpful" replies. Thanks....!!! https://vprhlabs.blogspot.in/
JohannesBernhar
Contributor
Contributor
Jump to solution

Hi Haridas,

thank you for help.

I just replaced the cert with a new one from our CA and restartet the Management Agents.

Thanks,

Johannes

0 Kudos