<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic vSAN Encryption - Failed to add more trusted certificate to cluster KMSClusterName. A cluster can configure at most 16 trusted certificates in VMware vSAN Discussions</title>
    <link>https://communities.vmware.com/t5/VMware-vSAN-Discussions/vSAN-Encryption-Failed-to-add-more-trusted-certificate-to/m-p/2749845#M12032</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have enabled vSAN Encryption using HyTrust Key Control for Key Management server. HyTrust KMS had small issue which was forcing me to refresh KMS certificate in vCenter and reestablish trust with KMS each time I reboot KMS server. I worked with HyTrust and they have fixed this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During testing in LAB, multiple times I restarted KMS, refreshed KMS certificate to established trust. Now if I try to refresh certificate am getting below error in vCenter web client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="pastedImage_0.png"&gt;&lt;img src="https://communities.vmware.com/t5/image/serverpage/image-id/79714iB0664932C34CF2BA/image-size/large?v=v2&amp;amp;px=999" role="button" title="pastedImage_0.png" alt="pastedImage_0.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked the vpxd.log on vCenter which says... &lt;STRONG&gt;Failed to add more trusted certificate to cluster vlabKMS01. A cluster can configure at most 16 trusted certificates.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone knows how i can increase this 16 certificate limits?&lt;/P&gt;&lt;P&gt;where does cluster or vCenter store KMS server certificate?&lt;/P&gt;&lt;P&gt;How can I delete unused certificates of KMS server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:41.340Z info vpxd[7F7A8E9D3700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: KmipTrustCertificateDialogMediator:dr-1217:01-2f] [VpxLRO] -- BEGIN lro-1730902 -- ResourceModel -- cis.data.provider.ResourceModel.query -- 52cd417f-4036-bf4b-e92e-f47207d6980d(52211441-f4ca-278c-9c58-014cc5c88454)&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:41.340Z info vpxd[7F7A8E9D3700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: KmipTrustCertificateDialogMediator:dr-1217:01-2f] [VpxLRO] -- FINISH lro-1730902&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:41.345Z info vpxd[7F7A8FD7A700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: KmipTrustCertificateDialogMediator:dr-1217:VCenterKmipPropertyProvider:203173:430839-1609690-ngc:70055790-fb] [VpxLRO] -- BEGIN lro-1730903 -- CryptoManager -- vim.encryption.CryptoManagerKmip.retrieveKmipServerCert -- 52cd417f-4036-bf4b-e92e-f47207d6980d(52211441-f4ca-278c-9c58-014cc5c88454)&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:43.271Z error vpxd[7F7A8FD7A700] [Originator@6876 sub=CryptoManagerKmipWrapper opID=dam-auto-generated: KmipTrustCertificateDialogMediator:dr-1217:VCenterKmipPropertyProvider:203173:430839-1609690-ngc:70055790-fb] &lt;STRONG&gt;Failed to connect to key server, QLC_ERR_NEED_AUTH&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:45.833Z info vpxd[7F7A8FD7A700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: KmipTrustCertificateDialogMediator:dr-1217:VCenterKmipPropertyProvider:203173:430839-1609690-ngc:70055790-fb] [VpxLRO] -- FINISH lro-1730903&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.656Z info vpxd[7F7AB4ACB700] [Originator@6876 sub=vpxLro opID=KmipServerActionResolver-apply-1609697-ngc:70055791-6d] [VpxLRO] -- BEGIN lro-1730904 -- CryptoManager -- vim.encryption.CryptoManagerKmip.uploadKmipServerCert -- 52cd417f-4036-bf4b-e92e-f47207d6980d(52211441-f4ca-278c-9c58-014cc5c88454)&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.668Z error vpxd[7F7AB4ACB700] [Originator@6876 sub=CryptoManager opID=KmipServerActionResolver-apply-1609697-ngc:70055791-6d] &lt;STRONG&gt;Failed to add more trusted certificate to cluster vlabKMS01. A cluster can configure at most 16 trusted certificates.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.669Z info vpxd[7F7AB4ACB700] [Originator@6876 sub=vpxLro opID=KmipServerActionResolver-apply-1609697-ngc:70055791-6d] [VpxLRO] -- FINISH lro-1730904&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.669Z info vpxd[7F7AB4ACB700] [Originator@6876 sub=Default opID=KmipServerActionResolver-apply-1609697-ngc:70055791-6d] [VpxLRO] -- ERROR lro-1730904 -- &lt;STRONG&gt;CryptoManager -- vim.encryption.CryptoManagerKmip.uploadKmipServerCert: vim.fault.DatabaseError:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;--&amp;gt; Result:&lt;/P&gt;&lt;P&gt;--&amp;gt; (vim.fault.DatabaseError) {&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; faultCause = (vmodl.MethodFault) null, &lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; faultMessage = &amp;lt;unset&amp;gt;&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; msg = ""&lt;/P&gt;&lt;P&gt;--&amp;gt; }&lt;/P&gt;&lt;P&gt;--&amp;gt; Args:&lt;/P&gt;&lt;P&gt;--&amp;gt; &lt;/P&gt;&lt;P&gt;--&amp;gt; Arg cluster:&lt;/P&gt;&lt;P&gt;--&amp;gt; (vim.encryption.KeyProviderId) {&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; id = "vlabKMS01"&lt;/P&gt;&lt;P&gt;--&amp;gt; }&lt;/P&gt;&lt;P&gt;--&amp;gt; Arg certificate:&lt;/P&gt;&lt;P&gt;--&amp;gt; "-----BEGIN CERTIFICATE-----&lt;/P&gt;&lt;P&gt;xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&lt;/P&gt;&lt;P&gt;--&amp;gt; --&amp;gt; hL+qymRUCAzsiwwr/orCEXoZkgjO0XqBc2SGgdxA3CiXbO5An4N5PQ==&lt;/P&gt;&lt;P&gt;--&amp;gt; -----END CERTIFICATE-----&lt;/P&gt;&lt;P&gt;--&amp;gt; "&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.925Z info vpxd[7F7AB4846700] [Originator@6876 sub=vpxLro opID=combined(dam-auto-generated: ObjectPropertyFilter:dr-1231,dam-auto-generated: RecentItemsListener:dr-1219,dam-auto-generated: ObjectPropertyFilter:dr-1229,dam-auto-generated: ObjectPropertyFilter:dr-1225,dam-auto-generated: KmipServersListViewMediator:dr-1] [VpxLRO] -- BEGIN lro-1730905 -- ResourceModel -- cis.data.provider.ResourceModel.query -- 52cd417f-4036-bf4b-e92e-f47207d6980d(52211441-f4ca-278c-9c58-014cc5c88454)&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.926Z info vpxd[7F7AB4846700] [Originator@6876 sub=vpxLro opID=combined(dam-auto-generated: ObjectPropertyFilter:dr-1231,dam-auto-generated: RecentItemsListener:dr-1219,dam-auto-generated: ObjectPropertyFilter:dr-1229,dam-auto-generated: ObjectPropertyFilter:dr-1225,dam-auto-generated: KmipServersListViewMediator:dr-1] [VpxLRO] -- FINISH lro-1730905&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.936Z info vpxd[7F7AB525A700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: ObjectPropertyFilter:dr-1231:VchaPropertyProvider:203173:430847-1609700-ngc:70055793-e2] [VpxLRO] -- BEGIN lro-1730907 -- FailoverClusterConfigurator -- vim.vcha.FailoverClusterConfigurator.getConfig -- 52cd417f-4036-bf4b-e92e-f47207d6980d(52211441-f4ca-278c-9c58-014cc5c88454)&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.936Z info vpxd[7F7AB525A700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: ObjectPropertyFilter:dr-1231:VchaPropertyProvider:203173:430847-1609700-ngc:70055793-e2] [VpxLRO] -- FINISH lro-1730907&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.959Z info vpxd[7F7AB5056700] [Originator@6876 sub=vpxLro opID=combined(dam-auto-generated: GenerationNumbersMonitor:dr-1249,dam-auto-generated: ObjectPropertyFilter:dr-1247):01-40] [VpxLRO] -- BEGIN lro-1730909 -- ResourceModel -- cis.data.provider.ResourceModel.query -- 52cd417f-4036-bf4b-e92e-f47207d6980d(52211441-f4ca-278c-9c58-014cc5c88454)&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.959Z info vpxd[7F7AB5056700] [Originator@6876 sub=vpxLro opID=combined(dam-auto-generated: GenerationNumbersMonitor:dr-1249,dam-auto-generated: ObjectPropertyFilter:dr-1247):01-40] [VpxLRO] -- FINISH lro-1730909&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.974Z info vpxd[7F7A8F366700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: ObjectPropertyFilter:dr-1231:VchaPropertyProvider:203173:430847-1609702-ngc:70055793-ff] [VpxLRO] -- BEGIN lro-1730910 -- FailoverClusterManager -- vim.vcha.FailoverClusterManager.getClusterHealth -- 52cd417f-4036-bf4b-e92e-f47207d6980d(52211441-f4ca-278c-9c58-014cc5c88454)&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.974Z error vpxd[7F7A8F366700] [Originator@6876 sub=SoapAdapter opID=dam-auto-generated: ObjectPropertyFilter:dr-1231:VchaPropertyProvider:203173:430847-1609702-ngc:70055793-ff] Method vim.vcha.FailoverClusterManager.getClusterHealth threw undeclared fault of type vim.fault.InvalidState&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.974Z info vpxd[7F7A8F366700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: ObjectPropertyFilter:dr-1231:VchaPropertyProvider:203173:430847-1609702-ngc:70055793-ff] [VpxLRO] -- FINISH lro-1730910&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.975Z info vpxd[7F7A8F366700] [Originator@6876 sub=Default opID=dam-auto-generated: ObjectPropertyFilter:dr-1231:VchaPropertyProvider:203173:430847-1609702-ngc:70055793-ff] [VpxLRO] -- ERROR lro-1730910 -- FailoverClusterManager -- vim.vcha.FailoverClusterManager.getClusterHealth: vim.fault.InvalidState:&lt;/P&gt;&lt;P&gt;--&amp;gt; Result:&lt;/P&gt;&lt;P&gt;--&amp;gt; (vim.fault.InvalidState) {&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; faultCause = (vmodl.MethodFault) null, &lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; faultMessage = (vmodl.LocalizableMessage) [&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (vmodl.LocalizableMessage) {&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; key = "com.vmware.vim.vcha.error.clusterNotConfigured", &lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; arg = &amp;lt;unset&amp;gt;, &lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; message = &amp;lt;unset&amp;gt;&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ]&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; msg = ""&lt;/P&gt;&lt;P&gt;--&amp;gt; }&lt;/P&gt;&lt;P&gt;--&amp;gt; Args:&lt;/P&gt;&lt;P&gt;--&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Haridas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 21 Feb 2018 17:36:43 GMT</pubDate>
    <dc:creator>vHaridas</dc:creator>
    <dc:date>2018-02-21T17:36:43Z</dc:date>
    <item>
      <title>vSAN Encryption - Failed to add more trusted certificate to cluster KMSClusterName. A cluster can configure at most 16 trusted certificates</title>
      <link>https://communities.vmware.com/t5/VMware-vSAN-Discussions/vSAN-Encryption-Failed-to-add-more-trusted-certificate-to/m-p/2749845#M12032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have enabled vSAN Encryption using HyTrust Key Control for Key Management server. HyTrust KMS had small issue which was forcing me to refresh KMS certificate in vCenter and reestablish trust with KMS each time I reboot KMS server. I worked with HyTrust and they have fixed this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During testing in LAB, multiple times I restarted KMS, refreshed KMS certificate to established trust. Now if I try to refresh certificate am getting below error in vCenter web client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="pastedImage_0.png"&gt;&lt;img src="https://communities.vmware.com/t5/image/serverpage/image-id/79714iB0664932C34CF2BA/image-size/large?v=v2&amp;amp;px=999" role="button" title="pastedImage_0.png" alt="pastedImage_0.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked the vpxd.log on vCenter which says... &lt;STRONG&gt;Failed to add more trusted certificate to cluster vlabKMS01. A cluster can configure at most 16 trusted certificates.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone knows how i can increase this 16 certificate limits?&lt;/P&gt;&lt;P&gt;where does cluster or vCenter store KMS server certificate?&lt;/P&gt;&lt;P&gt;How can I delete unused certificates of KMS server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:41.340Z info vpxd[7F7A8E9D3700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: KmipTrustCertificateDialogMediator:dr-1217:01-2f] [VpxLRO] -- BEGIN lro-1730902 -- ResourceModel -- cis.data.provider.ResourceModel.query -- 52cd417f-4036-bf4b-e92e-f47207d6980d(52211441-f4ca-278c-9c58-014cc5c88454)&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:41.340Z info vpxd[7F7A8E9D3700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: KmipTrustCertificateDialogMediator:dr-1217:01-2f] [VpxLRO] -- FINISH lro-1730902&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:41.345Z info vpxd[7F7A8FD7A700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: KmipTrustCertificateDialogMediator:dr-1217:VCenterKmipPropertyProvider:203173:430839-1609690-ngc:70055790-fb] [VpxLRO] -- BEGIN lro-1730903 -- CryptoManager -- vim.encryption.CryptoManagerKmip.retrieveKmipServerCert -- 52cd417f-4036-bf4b-e92e-f47207d6980d(52211441-f4ca-278c-9c58-014cc5c88454)&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:43.271Z error vpxd[7F7A8FD7A700] [Originator@6876 sub=CryptoManagerKmipWrapper opID=dam-auto-generated: KmipTrustCertificateDialogMediator:dr-1217:VCenterKmipPropertyProvider:203173:430839-1609690-ngc:70055790-fb] &lt;STRONG&gt;Failed to connect to key server, QLC_ERR_NEED_AUTH&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:45.833Z info vpxd[7F7A8FD7A700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: KmipTrustCertificateDialogMediator:dr-1217:VCenterKmipPropertyProvider:203173:430839-1609690-ngc:70055790-fb] [VpxLRO] -- FINISH lro-1730903&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.656Z info vpxd[7F7AB4ACB700] [Originator@6876 sub=vpxLro opID=KmipServerActionResolver-apply-1609697-ngc:70055791-6d] [VpxLRO] -- BEGIN lro-1730904 -- CryptoManager -- vim.encryption.CryptoManagerKmip.uploadKmipServerCert -- 52cd417f-4036-bf4b-e92e-f47207d6980d(52211441-f4ca-278c-9c58-014cc5c88454)&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.668Z error vpxd[7F7AB4ACB700] [Originator@6876 sub=CryptoManager opID=KmipServerActionResolver-apply-1609697-ngc:70055791-6d] &lt;STRONG&gt;Failed to add more trusted certificate to cluster vlabKMS01. A cluster can configure at most 16 trusted certificates.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.669Z info vpxd[7F7AB4ACB700] [Originator@6876 sub=vpxLro opID=KmipServerActionResolver-apply-1609697-ngc:70055791-6d] [VpxLRO] -- FINISH lro-1730904&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.669Z info vpxd[7F7AB4ACB700] [Originator@6876 sub=Default opID=KmipServerActionResolver-apply-1609697-ngc:70055791-6d] [VpxLRO] -- ERROR lro-1730904 -- &lt;STRONG&gt;CryptoManager -- vim.encryption.CryptoManagerKmip.uploadKmipServerCert: vim.fault.DatabaseError:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;--&amp;gt; Result:&lt;/P&gt;&lt;P&gt;--&amp;gt; (vim.fault.DatabaseError) {&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; faultCause = (vmodl.MethodFault) null, &lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; faultMessage = &amp;lt;unset&amp;gt;&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; msg = ""&lt;/P&gt;&lt;P&gt;--&amp;gt; }&lt;/P&gt;&lt;P&gt;--&amp;gt; Args:&lt;/P&gt;&lt;P&gt;--&amp;gt; &lt;/P&gt;&lt;P&gt;--&amp;gt; Arg cluster:&lt;/P&gt;&lt;P&gt;--&amp;gt; (vim.encryption.KeyProviderId) {&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; id = "vlabKMS01"&lt;/P&gt;&lt;P&gt;--&amp;gt; }&lt;/P&gt;&lt;P&gt;--&amp;gt; Arg certificate:&lt;/P&gt;&lt;P&gt;--&amp;gt; "-----BEGIN CERTIFICATE-----&lt;/P&gt;&lt;P&gt;xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&lt;/P&gt;&lt;P&gt;--&amp;gt; --&amp;gt; hL+qymRUCAzsiwwr/orCEXoZkgjO0XqBc2SGgdxA3CiXbO5An4N5PQ==&lt;/P&gt;&lt;P&gt;--&amp;gt; -----END CERTIFICATE-----&lt;/P&gt;&lt;P&gt;--&amp;gt; "&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.925Z info vpxd[7F7AB4846700] [Originator@6876 sub=vpxLro opID=combined(dam-auto-generated: ObjectPropertyFilter:dr-1231,dam-auto-generated: RecentItemsListener:dr-1219,dam-auto-generated: ObjectPropertyFilter:dr-1229,dam-auto-generated: ObjectPropertyFilter:dr-1225,dam-auto-generated: KmipServersListViewMediator:dr-1] [VpxLRO] -- BEGIN lro-1730905 -- ResourceModel -- cis.data.provider.ResourceModel.query -- 52cd417f-4036-bf4b-e92e-f47207d6980d(52211441-f4ca-278c-9c58-014cc5c88454)&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.926Z info vpxd[7F7AB4846700] [Originator@6876 sub=vpxLro opID=combined(dam-auto-generated: ObjectPropertyFilter:dr-1231,dam-auto-generated: RecentItemsListener:dr-1219,dam-auto-generated: ObjectPropertyFilter:dr-1229,dam-auto-generated: ObjectPropertyFilter:dr-1225,dam-auto-generated: KmipServersListViewMediator:dr-1] [VpxLRO] -- FINISH lro-1730905&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.936Z info vpxd[7F7AB525A700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: ObjectPropertyFilter:dr-1231:VchaPropertyProvider:203173:430847-1609700-ngc:70055793-e2] [VpxLRO] -- BEGIN lro-1730907 -- FailoverClusterConfigurator -- vim.vcha.FailoverClusterConfigurator.getConfig -- 52cd417f-4036-bf4b-e92e-f47207d6980d(52211441-f4ca-278c-9c58-014cc5c88454)&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.936Z info vpxd[7F7AB525A700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: ObjectPropertyFilter:dr-1231:VchaPropertyProvider:203173:430847-1609700-ngc:70055793-e2] [VpxLRO] -- FINISH lro-1730907&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.959Z info vpxd[7F7AB5056700] [Originator@6876 sub=vpxLro opID=combined(dam-auto-generated: GenerationNumbersMonitor:dr-1249,dam-auto-generated: ObjectPropertyFilter:dr-1247):01-40] [VpxLRO] -- BEGIN lro-1730909 -- ResourceModel -- cis.data.provider.ResourceModel.query -- 52cd417f-4036-bf4b-e92e-f47207d6980d(52211441-f4ca-278c-9c58-014cc5c88454)&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.959Z info vpxd[7F7AB5056700] [Originator@6876 sub=vpxLro opID=combined(dam-auto-generated: GenerationNumbersMonitor:dr-1249,dam-auto-generated: ObjectPropertyFilter:dr-1247):01-40] [VpxLRO] -- FINISH lro-1730909&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.974Z info vpxd[7F7A8F366700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: ObjectPropertyFilter:dr-1231:VchaPropertyProvider:203173:430847-1609702-ngc:70055793-ff] [VpxLRO] -- BEGIN lro-1730910 -- FailoverClusterManager -- vim.vcha.FailoverClusterManager.getClusterHealth -- 52cd417f-4036-bf4b-e92e-f47207d6980d(52211441-f4ca-278c-9c58-014cc5c88454)&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.974Z error vpxd[7F7A8F366700] [Originator@6876 sub=SoapAdapter opID=dam-auto-generated: ObjectPropertyFilter:dr-1231:VchaPropertyProvider:203173:430847-1609702-ngc:70055793-ff] Method vim.vcha.FailoverClusterManager.getClusterHealth threw undeclared fault of type vim.fault.InvalidState&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.974Z info vpxd[7F7A8F366700] [Originator@6876 sub=vpxLro opID=dam-auto-generated: ObjectPropertyFilter:dr-1231:VchaPropertyProvider:203173:430847-1609702-ngc:70055793-ff] [VpxLRO] -- FINISH lro-1730910&lt;/P&gt;&lt;P&gt;2018-02-21T12:39:47.975Z info vpxd[7F7A8F366700] [Originator@6876 sub=Default opID=dam-auto-generated: ObjectPropertyFilter:dr-1231:VchaPropertyProvider:203173:430847-1609702-ngc:70055793-ff] [VpxLRO] -- ERROR lro-1730910 -- FailoverClusterManager -- vim.vcha.FailoverClusterManager.getClusterHealth: vim.fault.InvalidState:&lt;/P&gt;&lt;P&gt;--&amp;gt; Result:&lt;/P&gt;&lt;P&gt;--&amp;gt; (vim.fault.InvalidState) {&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; faultCause = (vmodl.MethodFault) null, &lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; faultMessage = (vmodl.LocalizableMessage) [&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (vmodl.LocalizableMessage) {&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; key = "com.vmware.vim.vcha.error.clusterNotConfigured", &lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; arg = &amp;lt;unset&amp;gt;, &lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; message = &amp;lt;unset&amp;gt;&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; }&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ]&lt;/P&gt;&lt;P&gt;--&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; msg = ""&lt;/P&gt;&lt;P&gt;--&amp;gt; }&lt;/P&gt;&lt;P&gt;--&amp;gt; Args:&lt;/P&gt;&lt;P&gt;--&amp;gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Haridas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Feb 2018 17:36:43 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSAN-Discussions/vSAN-Encryption-Failed-to-add-more-trusted-certificate-to/m-p/2749845#M12032</guid>
      <dc:creator>vHaridas</dc:creator>
      <dc:date>2018-02-21T17:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: vSAN Encryption - Failed to add more trusted certificate to cluster KMSClusterName. A cluster can configure at most 16 trusted certificates</title>
      <link>https://communities.vmware.com/t5/VMware-vSAN-Discussions/vSAN-Encryption-Failed-to-add-more-trusted-certificate-to/m-p/2749846#M12033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;Hi vHaridas,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial, helvetica, sans-serif;"&gt;Is this test only or prod? If test only, you can reset your KMS server to delete the old certs, which still count against the total number of certs. &lt;SPAN style="color: #000000; font-size: 12.7px;"&gt;You can remove all keys by resetting the KMIP server. Go to Settings -&amp;gt; KMIP Server Settings, then click the "Reset KMIP Server" button. This will remove all keys on HyTrust, so &lt;/SPAN&gt;&lt;STRONG style="color: #000000; font-family: sans-serif; font-size: 12.7px;"&gt;DO NOT DO THIS ON PRODUCTION SERVER!&lt;/STRONG&gt;&lt;SPAN style="color: #000000; font-size: 12.7px;"&gt;. After the reset, Change state to "Enabled", and click the "Apply" button.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12.7px; font-family: arial, helvetica, sans-serif;"&gt;In VC, you should be able to see the certs in the UI. Administration&amp;gt;System Configuration&amp;gt;nodes. Select VC&amp;gt;Manage&amp;gt;Certificate Authority.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12.7px; font-family: arial, helvetica, sans-serif;"&gt;AFAIK, VMCA uses OpenSSL, so I'm assuming it gets the limits from it. &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Feb 2018 18:13:20 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSAN-Discussions/vSAN-Encryption-Failed-to-add-more-trusted-certificate-to/m-p/2749846#M12033</guid>
      <dc:creator>GreatWhiteTec</dc:creator>
      <dc:date>2018-02-21T18:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: vSAN Encryption - Failed to add more trusted certificate to cluster KMSClusterName. A cluster ca</title>
      <link>https://communities.vmware.com/t5/VMware-vSAN-Discussions/vSAN-Encryption-Failed-to-add-more-trusted-certificate-to/m-p/2991303#M15696</link>
      <description>&lt;P&gt;A bit of an old post, but what if this is a production machine where you can't lose access to the keys?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Oct 2023 00:21:23 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSAN-Discussions/vSAN-Encryption-Failed-to-add-more-trusted-certificate-to/m-p/2991303#M15696</guid>
      <dc:creator>AdamKithcart</dc:creator>
      <dc:date>2023-10-17T00:21:23Z</dc:date>
    </item>
  </channel>
</rss>

