VMware Cloud Community
bwaller84
Contributor
Contributor

Migrating/Upgrading Windows 6.5 to vcsa 6.7 fails at Starting VMware Authentication Framework...

I migrated to external PSC to 6.7u3 before attempting to do the same for vCenter itself. I keep getting an error at Starting VMware Authentication Framework. The Error that comes up is:

Failed to force refresh TRUSTED_ROOTS Error 183

DNS is working. I can ping the host name of the vcenter server, and its alias, they both come back as responsive.

Here are the error logs from the migration assistant:

error file:

No file found matching /etc/vmware/install-defaults/cm.url

No file found matching /etc/vmware-vpx/vcdb.properties

No file found matching /etc/vmware-vpx/vc-extn-cisreg.prop

error-ignored file:

No file found matching /var/log/analytics/*

No file found matching /etc/vmware/vmware-analytics/*

No file found matching /etc/vmware/vmware-analytics/agents/*

No file found matching /var/log/vmware/analytics/*

No file found matching /var/log/vmware/applmgmt/cli/*

No file found matching /storage/applmgmt/backup_restore/*

No file found matching /var/log/vmware/vmware-bigsister.data*

No file found matching /var/log/firstboot/certificatemanagement_firstboot*.log

No file found matching /var/log/vmware/certificatemanagement/*

No file found matching /var/log/vmware/cm/*

No file found matching /var/log/vmware/cm/firstboot/*

No file found matching /etc/vmware\vmware-eam\dbmigrate

No file found matching /etc/vmware\vmware-eam\catalina.properties

No file found matching /etc/vmware\vmware-eam\eam.properties

No file found matching /etc/vmware\vmware-eam\eam-vim.properties

No file found matching /etc/vmware\vmware-eam\features.json

No file found matching /etc/vmware\vmware-eam\features.properties

No file found matching /etc/vmware\vmware-eam\log4j.properties

No file found matching /etc/vmware\vmware-eam\logging.properties

No file found matching /etc/vmware\vmware-eam\version

No file found matching /etc/vmware\vmware-eam\firstboot\eamspec.properties

No file found matching /etc/vmware\vmware-eam\firstboot\extension\extension.xml.installer

No file found matching /var/log\eam

No file found matching /var/log/firstboot/imagebuilder*

No file found matching /etc/vmware/vmware-imagebuilder/

Cmd "/usr/lib/vmware-imagebuilder/bin/cmdlets.py --dump-database" failed with exit code 1

Cmd "/usr/lib/vmware-cm/bin/cmlookup -Dcm.url=http://localhost:18090/cm/sdk -Dprop=/usr/lib/vmware-cm/conf/cm.properties -Dlookup=all -Dcm.conn.attempts=1" failed with exit code 1

No file found matching /var/log/vmware/vmware-mbcs/*

No file found matching /var/log/vmware/mbcs/*

No file found matching /var/log/mbcs/*

No file found matching /var/log/vmware/netdumper/*

No file found matching /var/core/netdumps/*

No file found matching /var/log/vsphere-client/

No file found matching /var/log/vmware/perfcharts/*

No file found matching /var/log/perfcharts/*

No file found matching /etc/vmware-pod/ssl/rui.crt

No file found matching /var/log/rhttpproxy/*

No file found matching /etc/vmware-rhttpproxy/pc.properties

No file found matching /etc/vmware/vmware-rhttpproxy/endpoints.conf.d/*

No file found matching /etc/vmware/vmware-rhttpproxy/config.xml

No file found matching /etc/vmware/vmware-rhttpproxy/pc.properties

No file found matching /var/log/vmware/sca/*

No file found matching /usr/lib/vmware-sca/wrapper/conf/*

No file found matching /etc/vmware-sca/services/*

No file found matching /etc/vmware-sca/health/*

No file found matching /var/log/vmware/vmware-sps/*

No file found matching /var/log/vmware/applmgmt/StatsMonitor*

No file found matching /etc/crontab

No file found matching /etc/cron.monthly/*

No file found matching /etc/modprobe.conf*

No file found matching /etc/hosts.deny

No file found matching /var/log/boot*

No file found matching /var/log/secure*

No file found matching /var/log/sa/*

No file found matching /var/log/vmware/vami/*

No file found matching /var/log/.*

No file found matching /var/sa/*

Cmd "/usr/bin/journalctl -b -1" failed with exit code 1

Cmd "/usr/bin/journalctl -b -2" failed with exit code 1

No file found matching /var/log/commit/*

No file found matching /var/log/cloudvm/*

No file found matching /var/log/restore/*

No file found matching /var/log/prefreeze/*

No file found matching /var/log/postthaw/*

Error running command $VMWARE_CIS_HOME\bin\service-control.bat --status --all

No file found matching /var/log/vmware/vSphere-TlsReconfigurator/*

No file found matching /var/log/firstboot/topologysvc_firstboot*.log

No file found matching /var/log/vmware/topologysvc/*

No file found matching /etc/vmware/vmware-vapi/*

No file found matching /var/log/vapi

No file found matching /storage/vcha/

Cmd "/usr/lib/vmware-vcha/scripts/vcha-vc-support peer" failed with exit code 1

Cmd "/usr/lib/vmware-vcha/scripts/vcha-vc-support witness" returned no information, don't collect file commands/vcha-vc-support_witness.tgz for this cmd.

Cmd "/usr/lib/vmware-content-library/support/dump-content-library-thread.sh" failed with exit code 1

No file found matching /var/log/vmware/vpxd/vlf

No file found matching /var/log/vmware/vpxd/vlf-ts

No file found matching /var/log/vmware-vpx/vlf

No file found matching /var/log/vmware-vpx/vlf-ts

No file found matching /var/log/vmware-vmafd/*.log

No file found matching /var/log/vmware-vmca/*.log

No file found matching /var/log/vmware-vmdns/*.log

No file found matching /var/log/syslog.*

No file found matching /var/log/vmware/vmca/*

No file found matching /var/log/vmware/vmdns/*

No file found matching /var/log/vmware/vmcad/*

No file found matching /var/log/certificate-manager.log

No file found matching /var/log/vmware/vmdird/*

No file found matching /var/log/vmware/vmdnsd/*

No file found matching /var/log/vmafdd/*

No file found matching /var/log/vmca/*

No file found matching /var/log/vmdird/*

No file found matching /var/log/vmdns/*

No file found matching /usr/lib/vmware-vmafd/share/config/vmafd.reg

No file found matching /usr/lib/vmware-vmca/share/config/vmca.reg

No file found matching /usr/lib/vmware-vmdns/share/config/vmdns.reg

Error running command reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VMwareAfdService /s

Error running command reg query HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\VMwareDNSService /s

Cmd "/opt/likewise/bin/lwregshell ls HKEY_THIS_MACHINE\services\vmdns\parameters" failed with exit code 252

No file found matching /var/log/firstboot/vmcam-firstboot*.log

No file found matching /var/log/vmware-vmcam/*.log

No file found matching /var/log/syslog.*

No file found matching /var/log/vmware/vmcam/*

No file found matching /var/log/vmware/vmcamd/*

No file found matching /var/log/vmcamd/*

No file found matching /storage/vmware-vmon/*

No file found matching /var/log/vmon/

Cmd "/bin/vicfg-snmp --test" failed with exit code 1

Cmd "/bin/df -h /var/spool/snmp" failed with exit code 1

No file found matching /etc/vmware-vpx/ssl/rui.crt

No file found matching /etc/vmware-vpx/ssl/vcsoluser.crt

Cmd "/usr/bin/python /usr/lib/vmware-vpx/py/collect_vpxd_log.py" returned no information, don't collect file var/log/vmware/vpxd/vpxdLogFromCustomDir.tgz for this cmd.

No file found matching /var/log/vmware/journal/*

No file found matching /var/core/core.vpxd*

No file found matching /var/log/vmware/vctop/

No file found matching /etc/vmware-vpxd-svcs/ssl/invsvc.crt

No file found matching /usr/lib/vmware-vpxd-svcs/wrapper/conf/*

No file found matching /var/log/vmware/vsan-dps/*

No file found matching /var/log/vmware/vsan-health/*

Cmd "python /usr/lib/vmware-vpx/vsan-health/vsan-vc-health-status.py cluster-health" failed with exit code 1

No file found matching /etc/vmware\vmware-vsm

No file found matching /var/log\vsm

No file found matching /var/log/vsphere-ui/

Cmd "python /usr/lib/vmware-vpx/vsan-health/vsan-vc-health-status.py rvc-basic-support-information" failed with exit code 1

Cmd "/bin/rpm -qa --verify" failed with exit code 1

Reply
0 Kudos
2 Replies
AhmedIbrahimVMw
Enthusiast
Enthusiast

VMAFD is the service that that is responsible for accessing the certificate stores, the error message you provided shows that there's an issue refreshing the certificates from the certificate store.

Please file a Support Request with VMware GSS, and send them the error message "Failed to force refresh TRUSTED_ROOTS Error 183", and they will assist you in checking the certificate stores and fix any errors.

Regards,

Ahmed Atia Ibrahim

Reply
0 Kudos
Vijay2027
Expert
Expert

I've seen this issue before.

  • Unpublish all the certs from trusted roots store.
  • Re-publish only valid certs. (use dir-cli )
  • Now, using vecs-cli do  force-refresh and you should not see the message "Failed to force refresh TRUSTED_ROOTS Error 183" in vmafd log.
  • Once this is done, proceed with the upgrade.

Complex process. Suggest you to file a SR with GSS.

Reply
0 Kudos