VMware Cloud Community
erwabovm
Contributor
Contributor

vRO Certficate Request

I have a Powershell script that im invoking from vRO with the external script workflow. This script does a few things but of the things it does is request a cert from a CA using certutil.exe. When I run this from ISE or Powershell on the PowerShell host it works fine....when I call this from vRO it gets hung upon this line

"certreq  -submit -attrib CertificateTemplate:$CATemplate -config $OnlineCA $CertificateREQ $CertificateCER"

My variable are all correct, but it seems that it has something to do with the security context that is trying to call to the CA when its issued remotely from vRO. In any case  I just CANT get this one section to work?

Any idea?

0 Kudos
1 Reply
erwabovm
Contributor
Contributor

Here is what is in LOG:

2017-10-18 12:37:41.945-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] response code 200

 

2017-10-18 12:37:41.946-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] Header null --> HTTP/1.1 200

 

2017-10-18 12:37:41.946-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] Header Content-Type --> application/soap+xml;charset=UTF-8

 

2017-10-18 12:37:41.947-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] Header WWW-Authenticate --> Kerberos oYG3MIG0oAMKAQChCwYJKoZIhvcSAQICooGfBIGcYIGZBgkqhkiG9xIBAgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKicQRvY+yfVZZtZoKhH2m36IOg+LJmOBcZDM3Evm/yw/HhUPlyRuK6Ev83xAwZreT4nBoqljKlSSYH74bnJm0L0uFWnkjnUKd0fCOqYH9G1S624aIP0zvcbJpfcX12wtpfMBQlQe/wKipmAnoNA7N3xMn3

 

2017-10-18 12:37:41.948-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] Header Server --> Microsoft-HTTPAPI/2.0

 

2017-10-18 12:37:41.949-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] Header Date --> Wed, 18 Oct 2017 16:37:41 GMT

 

2017-10-18 12:37:41.949-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] Header Content-Length --> 1326

 

2017-10-18 12:37:41.949-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] send message:response <s:Envelope xml:lang=undefineden-USundefined xmlns:s=undefinedhttp://www.w3.org/2003/05/soap-envelopeundefined xmlns:a=undefinedhttp://schemas.xmlsoap.org/ws/2004/08/addressingundefined xmlns:w=undefinedhttp://schemas.dmtf.org/wbem/wsman/1/wsman.xsdundefined xmlns:rsp=undefinedhttp://schemas.microsoft.com/wbem/wsman/1/windows/shellundefined xmlns:p=undefinedhttp://schemas.microsoft.com/wbem/wsman/1/wsman.xsdundefined><s:Header><a:Action>http://schemas.microsoft.com/wbem/wsman/1/windows/shell/ReceiveResponse</a:Action><a:MessageID>uuid:126B0E97-A16B-48B3-8F9F-F9827D867426</a:MessageID><a:To>http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</a:To><a:RelatesTo>uuid:9303F33A-1C42-4120-A5C8-46FC586B5702</a:RelatesTo></s:Header><s:Body><rsp:ReceiveResponse><rsp:Stream Name=undefinedstdoutundefined CommandId=undefined957DB450-3F4E-4C84-BB24-57A6EC1B86B1undefined>X0ZfUkVDXw==</rsp:Stream><rsp:Stream Name=undefinedstdoutundefined CommandId=undefined957DB450-3F4E-4C84-BB24-57A6EC1B86B1undefined>Cg==</rsp:Stream><rsp:Stream Name=undefinedstdoutundefined CommandId=undefined957DB450-3F4E-4C84-BB24-57A6EC1B86B1undefined>Cg==</rsp:Stream><rsp:Stream Name=undefinedstdoutundefined CommandId=undefined957DB450-3F4E-4C84-BB24-57A6EC1B86B1undefined>PT09PT09PT09PT09UkVTVUxUX0RFTElNSVRFUl9TVEFSVD09PT09PT09PT0K</rsp:Stream><rsp:CommandState CommandId=undefined957DB450-3F4E-4C84-BB24-57A6EC1B86B1undefined State=undefinedhttp://schemas.microsoft.com/wbem/wsman/1/windows/shell/CommandState/Runningundefined></rsp:CommandState></rsp:ReceiveResponse></s:Body></s:Envelope>

 

2017-10-18 12:37:41.950-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [WinRmPowerShellClient] handleStream STDOUT buffer _F_REC_

============RESULT_DELIMITER_START==========

 

2017-10-18 12:37:41.951-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [WinRmPowerShellClient] handleStream STDERR buffer

 

2017-10-18 12:37:41.951-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [KerberosTokenGenerator] Kerberos login name: ebojonellx@mydomain.com

 

2017-10-18 12:37:41.986-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] send message to https://Server01.mydomain.com:5986/wsman:request <?xml version=undefined1.0undefined encoding=undefinedUTF-8undefined?>

<env:Envelope xmlns:env=undefinedhttp://www.w3.org/2003/05/soap-envelopeundefined>

  <env:Header>

    <a:To xmlns:a=undefinedhttp://schemas.xmlsoap.org/ws/2004/08/addressingundefined>https://Server01.mydomain.com:5986/wsman</a:To>

    <a:ReplyTo xmlns:a=undefinedhttp://schemas.xmlsoap.org/ws/2004/08/addressingundefined>

      <a:Address mustUnderstand=undefinedtrueundefined>http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</a:Address>

    </a:ReplyTo>

    <w:MaxEnvelopeSize xmlns:w=undefinedhttp://schemas.dmtf.org/wbem/wsman/1/wsman.xsdundefined mustUnderstand=undefinedtrueundefined>153600</w:MaxEnvelopeSize>

    <a:MessageID xmlns:a=undefinedhttp://schemas.xmlsoap.org/ws/2004/08/addressingundefined>uuid:9303F33A-1C42-4120-A5C8-46FC586B5702</a:MessageID>

    <w:Locale xmlns:w=undefinedhttp://schemas.dmtf.org/wbem/wsman/1/wsman.xsdundefined mustUnderstand=undefinedfalseundefined xml:lang=undefineden-USundefined/>

    <p:DataLocale xmlns:p=undefinedhttp://schemas.microsoft.com/wbem/wsman/1/wsman.xsdundefined mustUnderstand=undefinedfalseundefined xml:lang=undefineden-USundefined/>

    <w:OperationTimeout xmlns:w=undefinedhttp://schemas.dmtf.org/wbem/wsman/1/wsman.xsdundefined>PT180.000S</w:OperationTimeout>

    <a:Action xmlns:a=undefinedhttp://schemas.xmlsoap.org/ws/2004/08/addressingundefined mustUnderstand=undefinedtrueundefined>http://schemas.microsoft.com/wbem/wsman/1/windows/shell/Receive</a:Action>

    <w:SelectorSet xmlns:w=undefinedhttp://schemas.dmtf.org/wbem/wsman/1/wsman.xsdundefined>

      <w:Selector Name=undefinedShellIdundefined>D49C7900-7627-4FFB-BAD4-8A81E4B3A313</w:Selector>

    </w:SelectorSet>

    <w:ResourceURI xmlns:w=undefinedhttp://schemas.dmtf.org/wbem/wsman/1/wsman.xsdundefined mustUnderstand=undefinedtrueundefined>http://schemas.microsoft.com/wbem/wsman/1/windows/shell/cmd</w:ResourceURI>

  </env:Header>

  <env:Body>

    <rsp:Receive xmlns:rsp=undefinedhttp://schemas.microsoft.com/wbem/wsman/1/windows/shellundefined>

      <rsp:DesiredStream CommandId=undefined957DB450-3F4E-4C84-BB24-57A6EC1B86B1undefined>stdout stderr</rsp:DesiredStream>

    </rsp:Receive>

  </env:Body>

</env:Envelope>

2017-10-18 12:37:41.945-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] response code 200

 

2017-10-18 12:37:41.946-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] Header null --> HTTP/1.1 200

 

2017-10-18 12:37:41.946-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] Header Content-Type --> application/soap+xml;charset=UTF-8

 

2017-10-18 12:37:41.947-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] Header WWW-Authenticate --> Kerberos oYG3MIG0oAMKAQChCwYJKoZIhvcSAQICooGfBIGcYIGZBgkqhkiG9xIBAgICAG+BiTCBhqADAgEFoQMCAQ+iejB4oAMCARKicQRvY+yfVZZtZoKhH2m36IOg+LJmOBcZDM3Evm/yw/HhUPlyRuK6Ev83xAwZreT4nBoqljKlSSYH74bnJm0L0uFWnkjnUKd0fCOqYH9G1S624aIP0zvcbJpfcX12wtpfMBQlQe/wKipmAnoNA7N3xMn3

 

2017-10-18 12:37:41.948-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] Header Server --> Microsoft-HTTPAPI/2.0

 

2017-10-18 12:37:41.949-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] Header Date --> Wed, 18 Oct 2017 16:37:41 GMT

 

2017-10-18 12:37:41.949-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] Header Content-Length --> 1326

 

2017-10-18 12:37:41.949-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] send message:response <s:Envelope xml:lang=undefineden-USundefined xmlns:s=undefinedhttp://www.w3.org/2003/05/soap-envelopeundefined xmlns:a=undefinedhttp://schemas.xmlsoap.org/ws/2004/08/addressingundefined xmlns:w=undefinedhttp://schemas.dmtf.org/wbem/wsman/1/wsman.xsdundefined xmlns:rsp=undefinedhttp://schemas.microsoft.com/wbem/wsman/1/windows/shellundefined xmlns:p=undefinedhttp://schemas.microsoft.com/wbem/wsman/1/wsman.xsdundefined><s:Header><a:Action>http://schemas.microsoft.com/wbem/wsman/1/windows/shell/ReceiveResponse</a:Action><a:MessageID>uuid:126B0E97-A16B-48B3-8F9F-F9827D867426</a:MessageID><a:To>http://schemas.xmlsoap.org/ws/2004/08/addressing/role/anonymous</a:To><a:RelatesTo>uuid:9303F33A-1C42-4120-A5C8-46FC586B5702</a:RelatesTo></s:Header><s:Body><rsp:ReceiveResponse><rsp:Stream Name=undefinedstdoutundefined CommandId=undefined957DB450-3F4E-4C84-BB24-57A6EC1B86B1undefined>X0ZfUkVDXw==</rsp:Stream><rsp:Stream Name=undefinedstdoutundefined CommandId=undefined957DB450-3F4E-4C84-BB24-57A6EC1B86B1undefined>Cg==</rsp:Stream><rsp:Stream Name=undefinedstdoutundefined CommandId=undefined957DB450-3F4E-4C84-BB24-57A6EC1B86B1undefined>Cg==</rsp:Stream><rsp:Stream Name=undefinedstdoutundefined CommandId=undefined957DB450-3F4E-4C84-BB24-57A6EC1B86B1undefined>PT09PT09PT09PT09UkVTVUxUX0RFTElNSVRFUl9TVEFSVD09PT09PT09PT0K</rsp:Stream><rsp:CommandState CommandId=undefined957DB450-3F4E-4C84-BB24-57A6EC1B86B1undefined State=undefinedhttp://schemas.microsoft.com/wbem/wsman/1/windows/shell/CommandState/Runningundefined></rsp:CommandState></rsp:ReceiveResponse></s:Body></s:Envelope>

 

2017-10-18 12:37:41.950-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [WinRmPowerShellClient] handleStream STDOUT buffer _F_REC_

============RESULT_DELIMITER_START==========

 

2017-10-18 12:37:41.951-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [WinRmPowerShellClient] handleStream STDERR buffer

 

2017-10-18 12:37:41.951-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [KerberosTokenGenerator] Kerberos login name: ebojonellx@mydomain.com.COM

 

2017-10-18 12:37:41.986-0400 [WorkflowExecutorPool-Thread-58] DEBUG {ebojonellx@mydomain.com.com:Certificate Request:5d24b15b-bb16-4e71-bfb8-aa1b97e2cf21:token=8a8a8acc5f26d39c015f3058eb61079f} [JdkHttpConnector] send message to https://SERVER01.mydomain.com.com:5986/wsman:request <?xml version=undefined1.0undefined encoding=undefinedUTF-8undefined?>

0 Kudos