VMware Cloud Community
sbeaver
Leadership
Leadership
Jump to solution

Host certificate is different than web certificate registered into VA

Good day all,

I have a new vRA 7 install that was installed with self-sign certs and now while attempting to replace all the self-signed with signed certs I have an error that I just cannot seem to resolve.  On the certificated tab of the cafe appliance under Manage IaaS Component Certificates I am see the error " Remote host servername certificate is different than Web certificate registered into VA"

The Common name displayed is the individual host and not the VIP that shows up for the rest.  I have imported, provided thumbprint and generated new cert in attempted to try and get the values to change but so far no dice.  I am thinking the value is set in the postgres DB and that might not be getting updated with the certificate change.  The certificate is for the IaaS Web.

Anyone got any ideas how to update or possibly if needed update the database table.

Anyone seen this and have a fix?

Thanks

Steve

Steve Beaver
VMware Communities User Moderator
VMware vExpert 2009 - 2020
VMware NSX vExpert - 2019 - 2020
====
Co-Author of "VMware ESX Essentials in the Virtual Data Center"
(ISBN:1420070274) from Auerbach
Come check out my blog: [www.virtualizationpractice.com/blog|http://www.virtualizationpractice.com/blog/]
Come follow me on twitter http://www.twitter.com/sbeaver

**The Cloud is a journey, not a project.**
Reply
0 Kudos
1 Solution

Accepted Solutions
darrenoid
Enthusiast
Enthusiast
Jump to solution

Hello sbeaver,

In vRA 7 a new feature is that the IAAS certificates can be automatically registered through the VAMI. This did not work for me at all. When I imported the certificate in the VAMI, I got an error when it failed to change the IIS binding. When I tried to provide the thumbprint it failed and told me the thumbprint could not be found in the store.

I found this post which helped me realize I had to do it the old vra 6.x manual way:

vRA 7 certificate replacement error

Unfortunately the link in that post to the documentation does not work for me. I used the following blog post and vra documentation for an example:

Replacing vCAC 6.0 IaaS Certificates -

vRealize Automation 6.2 Documentation Center

Regards,

Darrenoid

View solution in original post

Reply
0 Kudos
3 Replies
darrenoid
Enthusiast
Enthusiast
Jump to solution

Hello sbeaver,

In vRA 7 a new feature is that the IAAS certificates can be automatically registered through the VAMI. This did not work for me at all. When I imported the certificate in the VAMI, I got an error when it failed to change the IIS binding. When I tried to provide the thumbprint it failed and told me the thumbprint could not be found in the store.

I found this post which helped me realize I had to do it the old vra 6.x manual way:

vRA 7 certificate replacement error

Unfortunately the link in that post to the documentation does not work for me. I used the following blog post and vra documentation for an example:

Replacing vCAC 6.0 IaaS Certificates -

vRealize Automation 6.2 Documentation Center

Regards,

Darrenoid

Reply
0 Kudos
sbeaver
Leadership
Leadership
Jump to solution

I will look into that thank you.  I am struggling getting the install to work.  Part of the process is VMware using a self-signed cert for the install and my install is failing because it did not trust the self-signed cert

Steve Beaver
VMware Communities User Moderator
VMware vExpert 2009 - 2020
VMware NSX vExpert - 2019 - 2020
====
Co-Author of "VMware ESX Essentials in the Virtual Data Center"
(ISBN:1420070274) from Auerbach
Come check out my blog: [www.virtualizationpractice.com/blog|http://www.virtualizationpractice.com/blog/]
Come follow me on twitter http://www.twitter.com/sbeaver

**The Cloud is a journey, not a project.**
Reply
0 Kudos
sbeaver
Leadership
Leadership
Jump to solution

In my case putting the certificate in the trusted people folder seemed to do the trick this time

Steve Beaver
VMware Communities User Moderator
VMware vExpert 2009 - 2020
VMware NSX vExpert - 2019 - 2020
====
Co-Author of "VMware ESX Essentials in the Virtual Data Center"
(ISBN:1420070274) from Auerbach
Come check out my blog: [www.virtualizationpractice.com/blog|http://www.virtualizationpractice.com/blog/]
Come follow me on twitter http://www.twitter.com/sbeaver

**The Cloud is a journey, not a project.**
Reply
0 Kudos