<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: vSphere Upgrade Pre-Check Failure - Certificate SAN DNS and FQDN Check in VMware vSphere™ Discussions</title>
    <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vSphere-Upgrade-Pre-Check-Failure-Certificate-SAN-DNS-and-FQDN/m-p/2949592#M44333</link>
    <description>&lt;P&gt;Thanks - I ran each step in the KB and all three outputs were set to the FQDN of the VCSA.&lt;/P&gt;&lt;P&gt;I used to have an external PSC but that was consolidated to an embedded maybe a year ago - this is the first major upgrade since that was performed - could that have caused an issue?&lt;/P&gt;&lt;P&gt;The only reference to the old external PSC is on the 'issuer' section of the certs, everything else is set to the FQDN of the VCSA.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jan 2023 17:09:10 GMT</pubDate>
    <dc:creator>AndyDodsworth</dc:creator>
    <dc:date>2023-01-19T17:09:10Z</dc:date>
    <item>
      <title>vSphere Upgrade Pre-Check Failure - Certificate SAN DNS and FQDN Check</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vSphere-Upgrade-Pre-Check-Failure-Certificate-SAN-DNS-and-FQDN/m-p/2949386#M44317</link>
      <description>&lt;P&gt;Hello - looking for some advice on an vCenter upgrade I'm attempting from 6.7 U3 to 7.0 U3.&lt;/P&gt;&lt;DIV&gt;I ran pre-checks using Skyline Health Diagnostics&amp;nbsp;and I have one pre-check failure:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;SPAN&gt;VC_UPC.VCSA.CertSANCheck: Certificate SAN DNS and FQDN Check&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;vCenter Server 7.0 requires Machine FQDN to be past of SubjectAltName of Certificate&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;SPAN&gt;KB Number:&amp;nbsp;&lt;A href="https://kb.vmware.com/s/article/2097936" target="_blank" rel="noopener"&gt;2097936&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;Resolution:&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;Certificate Requirements:&amp;nbsp;&lt;A href="https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.authentication.doc/GUID-DE49FBF5-E24A-462B-91DC-C4284D93F654.html" target="_blank" rel="noopener"&gt;https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.authentication.doc/GUID-DE49FBF5-E24A-462B-91DC-C4284D93F654.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Please read KB:&amp;nbsp;&lt;A href="https://kb.vmware.com/s/article/2097936" target="_blank" rel="noopener"&gt;https://kb.vmware.com/s/article/2097936&lt;/A&gt;&amp;nbsp;for more details on replacing certificates.&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;Investigation Details:&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;Data Collection Time: 2023-01-12T19:50:13&lt;/P&gt;&lt;P&gt;Certificate: vCenter Rhttpproxy TLS Certificate has no DNS Name in SubjectAltName&lt;/P&gt;&lt;P&gt;Certificate Subject Alternative Names&lt;/P&gt;Certificate FQDN SAN-DNS Status &lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;vCenter Rhttpproxy TLS Certificate&lt;/TD&gt;&lt;TD&gt;(&lt;EM&gt;correct FQDN - redacted&lt;/EM&gt;)&lt;/TD&gt;&lt;TD&gt;[]&lt;/TD&gt;&lt;TD&gt;RED&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;One of more Certificates on vCenter have no or incorrect DNS in SubjectAltName&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;I have checked the certs on the VCSA and the TRUSTED_ROOTS cert does indeed have a SAN set to the following (which I understand is the default):&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;SPAN&gt;X509v3 Subject Alternative Name:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="mailto:email%3Aemail@acme.com" target="_blank" rel="noopener"&gt;email:email@acme.com&lt;/A&gt;, IP Address:127.0.0.1&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;DIV&gt;But given, the error above appears to say the issue is with the vCenter Rhttpproxy TLS Certificate (which I'm not sure is a VCSA or ESXi cert?).&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;So my question is, which course of action would you recommend to fix this issue?&lt;/DIV&gt;&lt;DIV&gt;a) A complete renewal of all certs in the environment?&lt;/DIV&gt;&lt;DIV&gt;b) A refresh of the ESXi certs?&lt;/DIV&gt;&lt;DIV&gt;c) ?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;BTW - we're using VMCA-signed certs in this environment.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;TIA.&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 17:21:32 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vSphere-Upgrade-Pre-Check-Failure-Certificate-SAN-DNS-and-FQDN/m-p/2949386#M44317</guid>
      <dc:creator>AndyDodsworth</dc:creator>
      <dc:date>2023-01-18T17:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: vSphere Upgrade Pre-Check Failure - Certificate SAN DNS and FQDN Check</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vSphere-Upgrade-Pre-Check-Failure-Certificate-SAN-DNS-and-FQDN/m-p/2949405#M44319</link>
      <description>&lt;P&gt;Have you run through the steps in the following KB to see if the pnid matches....&amp;nbsp;&lt;A href="https://kb.vmware.com/s/article/50112870" target="_blank"&gt;https://kb.vmware.com/s/article/50112870&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 18:19:32 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vSphere-Upgrade-Pre-Check-Failure-Certificate-SAN-DNS-and-FQDN/m-p/2949405#M44319</guid>
      <dc:creator>compdigit44</dc:creator>
      <dc:date>2023-01-18T18:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: vSphere Upgrade Pre-Check Failure - Certificate SAN DNS and FQDN Check</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vSphere-Upgrade-Pre-Check-Failure-Certificate-SAN-DNS-and-FQDN/m-p/2949592#M44333</link>
      <description>&lt;P&gt;Thanks - I ran each step in the KB and all three outputs were set to the FQDN of the VCSA.&lt;/P&gt;&lt;P&gt;I used to have an external PSC but that was consolidated to an embedded maybe a year ago - this is the first major upgrade since that was performed - could that have caused an issue?&lt;/P&gt;&lt;P&gt;The only reference to the old external PSC is on the 'issuer' section of the certs, everything else is set to the FQDN of the VCSA.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 17:09:10 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vSphere-Upgrade-Pre-Check-Failure-Certificate-SAN-DNS-and-FQDN/m-p/2949592#M44333</guid>
      <dc:creator>AndyDodsworth</dc:creator>
      <dc:date>2023-01-19T17:09:10Z</dc:date>
    </item>
  </channel>
</rss>

