computer vCenter 6.0u2 - Certificate Tool - CSR certificate

Hello

Following the instructions here: https://kb.vmware.com/selfservice/search.do?cmd=displayKC & docType = kc & docTypeID = DT_KB_1_1 & externalId = 2112277

I want to generate machine CSR of the PSC.


So, option 1 to replace the Machine SSL, continue through. However, instead of the expected 'machine_ssl.csr' and 'machine_ssl.key', I find myself with 'vmca_issued_csr.csr' and 'vmca_issued_key.key '.

This seems odd, because it is what I expected for option 2, option 1.

Option 5 (replace user solution certs), generates:

  • 'machine.csr '.
  • "vsphere - webclient.csr" on the PSC

and

  • 'machine.csr '.
  • "vsphere - webclient.csr.
  • "vpxd.csr" and
  • "vpxd - extensions.csr" on the node of vCenter correctly...

But I expect to machine - ssl.csr somewhere.

No example of the PSC:

< host name >: / usr/lib/vmware-vmca/bin #. -Certificate Manager

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _

|                                                                    |

|      Welcome to vSphere Certificate Manager 6.0 * |

|                                                                    |

|                  -Choose the operating mode |

|                                                                    |

                |      1. Replace the SSL of Machine certificate with certificate of custom |

|                                                                    |

|      2. replace VMCA root certificate with Custom signature |

|        Certificate and replace all certificates |

|                                                                    |

|      3. replace the SSL certificate with certificate VMCA Machine |

|                                                                    |

|      4 regenerate a new certificate root VMCA and |

|        replace all certificates |

|                                                                    |

|      5. Replace Solution user certificates with |

|        Custom certificate |

|                                                                    |

|      6. Replace Solution user with certificates VMCA certificates |

|                                                                    |

|      7 redo the last operation performed by the old re-publication |

|        certificates                                                |

|                                                                    |

|      8 reset all certificates |

|_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _|

Note: Use Ctrl-D to complete.

Option [1-8]: 1

Please provide valid SSO and VC privileged user credentials to perform certificate operations.

Enter the username [[email protected]]:[email protected]

Enter the password:

1. generate the certificate signing forced and new keys for the certificate SSL of Machine

2. the import or the personalized certificates and new key to replace the certificate SSL of Machine existing

The option [1 or 2]: 1

Please provide a directory location to write the CSR (s) and the PrivateKey (s) to:

Path to the output directory: / tmp/ssl/2

file certool.cfg exist, you want to reconfigure: Option [Y/N]? : N

2016-07 - 05T 03: 19:38.388Z order: [' / usr/lib/vmware-vmca/bin/certool ', '-genkey', '-privkey', ' /vmca_issued_key.key', '-pubkey ',' / tmp/pubkey.pub ']

2016-07 - 05T 03: 19:38.604Z done by running the command

2016-07 - 05T 03: 19:38.604Z order: [' / usr/lib/vmware-vmca/bin/certool ', '-gencsr', '-privkey', ' /vmca_issued_key.key', '-pubkey ',' / tmp/pubkey.pub ', '-config ',' / var/tmp/vmware/certool.cfg', '-csrfile ',' / tmp/ssl/2 /vmca_issued_csr.csr']

2016-07 - 05T 03: 19:38.717Z done by running the command

CSR generated: / tmp/ssl/2 /vmca_issued_csr.csr

1. continue to import custom certificates and new keys for the certificate SSL of Machine

2 output-Certificate Manager

The option [1 or 2]: 2

usatca4273: / usr/lib/vmware-vmca/bin # cd/tmp/ssl/2

usatca4273: / tmp/ssl/2 # ls

vmca_issued_csr. CSR vmca_issued_key.key

< host name >: / tmp/ssl/2 #.

Certool.cfg the contents hidden as for a customer.

The .csr returned to the request of the machine (vmca_issued_csr.csr) is now the new name for the machine - ssl.csr, or something is strange is going on with the update 2?

So it turns out that "vmware_issued_csr.csr" is the new "machine - ssl.csr. Curiously called, so I asked the KB update to reflect this change.

Tags: VMware

Similar Questions

  • Installing vCenter 4.0u2 with the remote server in SQL2008

    I've been running vCenter 4.0 for awhile with SQL Express on the same machine.  I installed SQL Server 2008 on a remote computer, detached and attached the SQL Express database to that server.

    I've implemented the SQL 2008 database with a SQL rather than a domain account authentication account because our domain accounts will expire every 90 days and I have no control over making an exception to this policy.

    I have tried everything point vCenter 4.0 to the new database using the instructions in the knowledge base, but it has always failed.  So I just uninstalled (who also failed and I had to manually get the rest but this is not the point of this post).  When I go to install vCenter 4.0u2 with SYSTEM defined as the user vCenter (again because of limitations of domain account and expire 90 days), it gets all the way up to the

    "

    25003.Setup failed to create the vCenter repository"

    and then breaks down.  It's probably something with the user accounts on SQL authentication and vCenter Server does not, but how can I work around this? If I do a local account on the vCenter server with the same name and password on the vCenter server and run it like this account which will solve the problem?

    Check here also, not exactly the question, but it can help to point you in the right direction.

    http://KB.VMware.com/kb/1017596

  • How do I trouble or set the computer to stop the certificate on my Windows XP errors

    I moved to a new area and since we got our computer back online I make a page that explains the certificate errors, start, it was when I tried to get into my mail, now it doesn, t come after deletion of cookies, but try to make a payment to my school he appeared again. Example: trying to make a payment online today at my school and this has happened, the option I have, is to go to the page that is not recommended and shows that it is not safe for private info, any help would be appreciated to fix this problem, thanks

    A description of the exact certificate error you get can help.
    Guess, it is possible that your root certificates will need to be updated.
    To do this, go to the following site:

    "Members of the certificate program root Windows.
      <>http://support.Microsoft.com/kb/931125 >

    Then look for the section titled: "root Update Package (planned for Windows XP only).
    Download the file specified in this link on your computer, and double-click to launch.
    This should update your root certificates.

    HTH,
    JW

  • HP mini 110 unlock, after successful computer unlock, website security certificate problem

    Web site security certificate problem

    Ok

  • Workstation 9: mouse leaves no window of computer virtual (Windows XP prompt, tools installed)

    Description of the problem:

    When the mouse is caught by the virtual machine, the mouse does not leave the VM when moved to the borders.

    Host operating system: Ubuntu 10.04 64bits, all installed updates. It happens with and without active Visual effects.

    Also this problem with Workstation 9.0 (e.x.p) WTP and 9.0.0 build-812388

    VMWare tools have been installed to the latest version.

    The problem is reproducible when creating the virtual machine to start from scratch with a CD Windows XP SP2 install with or without easy installation.

    I also tried to install tools before Windows updates, and after the installation of SP3.

    The following steps ALLOW the automatic ungrabbing but there other questions (could help determine the cause):

    Option 1:

    1. remove the hub USB of VM (this alone does not)

    2 uninstall VMWare pointing device driver

    3 reset

    -> After reboot the mouse pointer is able to ungrab automatically, however the mouse is slow

    -> Windows redétecte the VMMouse driver and moved again

    4 reboot

    -> back to the old behavior (impossible to ungrab automatically)

    Option 2:

    1 edit the VMX file:

    vmmouse. Present = "FALSE".

    Mouse.vUSB. Activate = "FALSE".

    2. start on XP

    -> managed to escape (automatic ungrab) borders

    -> mouse is slow, don't not ungrab when you try to click on the window in front of the VM host

    Any help would be appreciated! Automatic Ungrab is one of the most important elements to work seamlessly with a virtual machine...

    Great! This means that there is a button is physically stuck on your mouse, or there is software installed on your host computer that pretended force/a button down (not necessarily your click left or right buttons).

    If there is a button stuck on the physical mouse, set up with a different mouse should solve the problem.

    If the button stuck suite software, then you have to find it and uninstall it, or only work with this configuration option. Unfortunately, with this configuration option, when you click and drag in the virtual machine and hit the edge, you forced himself at the window, and instead, you will be ungrab. This may end up being an annoying quirk, that you will have to get used to.

    Don't worry about trying to install another virtual computer, it won't make a difference.

    "And do not hesitate to pass your ' Gaming Mouse ' definition back to 'Auto '.

  • Error in vCenter Preupgrade Agent-check tool - cannot verify the signature of the installer

    Hello

    during the preparation for the upgrade to vCenter Server 4.0 to 4.1 U1, I run the Preupgrade Agent-check tool vCenter. Postdated check step I get the following error:

    [VCAgentU:Error: P: 5] 2011-03-18 12:03:39.992 RMI error Vmomi.AgentManager.Upgrade - 13
    < type = "Vmomi.Fault.AgentInstallFailed error" >
    < message > cannot install the vCenter agent service. Cannot verify the signature of the installer < / Message >
    < DetailedMessage > cannot install the vCenter agent service. Cannot verify the signature of the installer
    < / DetailedMessage >
    < / error >

    What means error thies and what steps should I fix?

    Kind regards

    Sascha

    Hi Sasha,.

    I saw this question in a few places. I always look at what is the cause and I try to grab a Wireshark dump during execution of the agent pre-upgrade check tool.

    From what I see, there are two files being pushed down to/tmp/vmware-root/ha-agentmgr, but their content does not seem to be correct.

    What version of ESX/ESXi do you have? (Build number would be good to know)

  • Error replace the certificate SSL - inventory services with using SSL - please help automation tools

    I uses updated SSL tools to change the SSL to vCenter 5.5 certificate.

    Modification of SINGLE authentication certificate has been successful, but I'm having a problem with the inventory services.

    Error message below.

    ==================================================================

    4 update the inventory Service SSL certificate

    1. update the confidence of the inventory of Single Sign-On Service

    2. update the Service of Trust inventory to vCenter Server

    3 update the inventory Service SSL certificate

    4. back to the old inventory SSL Certificate Service

    5. return to the main menu to update other services

    The service chosen is: 3

    [Wednesday 3 December, 2014 - 13:49:12.88]: services that are delivered to market as part of thi

    operation s are: vCenter Inventory Service.

    Enter the location of the new inventory channel Service SSL: C:\certs\InventorySer

    vice\chain.PEM

    Enter the location of the new private key for the inventory Service: C:\certs\InventoryS

    ervice\rui - orig.key

    Enter the SSO administrator user (default value is: administrator@vsp)

    here.local):

    Enter the SSO administrator password (not displayed):

    [.] The supplied certificate string is valid.

    [Wednesday 3 December, 2014 - 13:49:44.41]: last update of functioning inventory Service SSL cert

    ificatsanitai re has failed:

    [Wednesday 3 December, 2014 - 13:49:44.42]: unable to determine if the inventory Service is registe

    Red with Single Sign-On - errorlevel is 1

    =================================================================

    Problem solved, as the vCenter my share of the same SSO domain environment is necessaio that certificcado the backend SSL is changed.

  • Error update vcenter SSL certificate?

    Hello people,

    I've recently upgraded to vcenter 5.1 U1a successfully.

    I'm following VMware articles and a popular blog to prepare and run the certificate VMware 1.0 automation tool.

    http://www.derekseaman.com/2012/09/VMware-vCenter-51-installation-part-2.html

    http://www.derekseaman.com/2013/04/using-VMware-vCenter-certificate.html

    Everything was pretty smooth up until I have to replace the the vcenter Server SSL certificate.  Option 2 vcenter update ssl.  See the attached photo.

    After the error, my vcenter service will not start.

    I tried to reset the password of database using vpxd.exe - p, but vcenter still does not start.

    I also checked that the correct service ID is matched between vpxd.cfg and LS_ServiceID.prop.

    Stuck at this point.  I have since went instant return, but try to see if anyone has any suggestions?

    Could this be type a bad password?

    Thank you!


    You mentioned the KB as well?

    http://KB.VMware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalID=2048202

    Concerning

    Girish

  • Re-use of vCenter SSO certificate

    I was banging my head against the deployment of the single sign-on with my installation of vCenter 5.1 certificates.

    I think I finally have a handle on how to do it using the SSL automation tool.

    So what I wanted to do was blow up all my servers and reinstall all.  I wanted to reuse the certificates that I have already created.

    I think that if I use the same IP address and host name I should be fine.  I'm going basic here?

    There will be no problem as long as CN has the FQDN of the server and the domain OR something that is unique for the SSO service. Just install the servers and redeploy certificates that you are used to.

  • VCenter Server 5.1 SSL certificate update - error

    Hi all

    We set up a new Windows 2008 R2 server as a vCenter Server 5.1

    Now, I try to install the new certificates for all parts of vCenter (server, inventory, web client service,...) with the Windows certification authority.

    I'm stuck at the update server certificate SSL vCenter with the 'Certificate SSL Automation Tool'.

    This is part 5. in this guide (5. the cmd screen shot):

    http://KB.VMware.com/selfservice/microsites/search.do?language=en_US & cmd = displayKC & externalId = 2041600 #updatestepsplanner

    All credentials are correct, but I still get the same error (vc-update - ssl.log):

    [26.04.2013 - 10:42:54, 99]: copy the new certificates and keys 'C:\ProgramData\VMware\VMware VirtualCenter\SSL. '... »
    [26.04.2013 - 10:42:55: 00]: creating the PKCS certificate file...
    Could not reload vCenter SSL certificates
    [26.04.2013 - 10:42:56: 22]: ""cannot reload the server vCenter SSL certificates. " The certificate could not be unique. » »
    [26.04.2013 - 10:42:56, 24]: new certificates and keys deleting...
    [26.04.2013 - 10:42:56: 25]: restoration of the certificates and the original keys...
    1 Datei () kopiert.
    1 Datei () kopiert.
    1 Datei () kopiert.
    [26.04.2013 - 10:42:56: 25]: attempt to restore...
    Could not reload vCenter SSL certificates
    [26.04.2013 - 10:42:57, 08]: ""cannot reload the server vCenter SSL certificates. " The certificate could not be unique. » »
    [26.04.2013 - 10:42:57: 10]: new certificates and keys deleting...
    [26.04.2013 - 10:42:57: 10]: restoration of the certificates and the original keys...
    1 Datei () kopiert.
    1 Datei () kopiert.
    1 Datei () kopiert.
    [10: 42:57, 13 - 26.04.2013]: failure of the update of the certificate of vCenter.

    So I tried the manual way, as it is mentioned in this guide:

    I'm stuck here too, get a 'result of Method Invocation: vpx.fault.SecurityConfigFault ' after ""Invoke method ': "

    1. Go to https://localhost/mob/?moid=vpxd-securitymanager & vmodl = 1 on the server vCenter Server and load the certificates for the configuration using the managed object browser.
    2. Click continue if you are prompted with a warning on this certificate.
    3. Enter a vCenter Server administrator user name and password when prompted.
    4. Click reloadSslCertificate.
    5. Click the calling method. If successful, the window displays this message: result of Invocation of method: Sub.


    I tried to fix this, but there is not really a solution for this:

    http://communities.VMware.com/thread/429035

    so, I need help with this question

    SOLVED!

    Steps to follow:

    1. stop the vCenter service

    2. search for your ID in LS_ServiceID.prop in the folder C:\ProgramData\VMware\VMware VirtualCenter

    3. copy this ID (e.g. {C4672589-9258-42B1-90E2-1EF268BBD402}: 5 )

    4. change your vpxd.cfg in the same folder and replace

    vCenterService

    with

    your ID

    5. start vCenter Service

    Then, the SSL automation tool works!

    You need to undo changes.

  • View 7 vCenter Server Can can't Verify Certificate

    We have a vCenter 6 and one instance of vCenter 5.5.  vCenter 6 Let check me the default self-signed CERT. vCenter 5.5 when you click on verify does nothing.  When you go to the server and change the 5.5, it still gives this error:

    "Eventually, a server vCenter no valid certificate. Please verify the identity of the vCenter Server partner. »

    I tried to uninstall and reinstall composer still nothing does not.  The 'view composer servers' Let's check me the certificate.  I guess another bug with Horizon view 7.

    It is actually not a bug. You should perhaps follow http://pubs.vmware.com/horizon-7-view/topic/com.vmware.ICbase/PDF/view-70-installation.pdf and enable TLSv1.0 on the login server as well as on the composer.

    André

  • Certificate management issues

    How to install a certificate in the Trusted Root Certification authorities store?

    Hello Uniquemissm,

    Thanks for posting on the Community Forums of Microsoft Vista.

    You can manually install the certificate in the certificates of Certification authorities store roots of trust on a computer by using the CertMgr tool.

    For more information about installing Certificate in the Certification Authorities certificate store trusted roots, see the link below: http://msdn.microsoft.com/en-us/library/aa906279.aspx 
    http://msdn.Microsoft.com/en-us/library/dd434709.aspx

    Also, visit the link below to find a community that will offer in support of your application.
    http://social.msdn.Microsoft.com/forums/en-us/categories

    It will be useful.

    Thank you and best regards,

    Srinivas
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think

  • Can't connect to SSL certificate re VMware Update Manager - utility

    In the context of http://KB.VMware.com/selfservice/microsites/search.do?cmd=displayKC & docType = kc & docTypeID = DT_KB_1_1 & externalId = 2037581 , I'm at step 7 where I enter the credentials for the VMwareUpdateManagerUtility.exe. It just hangs and ends by mistake.  I copied the new certificate SSL files above.  I have 2 errors different no matter what I try.

    Error 1: "cannot run vciInstallUtility."
    Error 2: "error: unknown vCenter Server error."
    For "vCenter Server IP address or name", I tried < FQDN vcenter >: 80, < vCenter IP >: 80, < vCenter fake DNS in the hosts file >: 80 and they all hang on for a few minutes and then give one of the errors.  VUM is installed on a separate computer vCenter virtual.  I did a complete reinstall of VUM.  I use vCenter and VUM 5.1.0 installation media - rates from 880471 since that's our motto.  I checked that port 80 is correct using this query on VCDB, SELECT VALUE FROM VPX_PARAMETER WHERE NAME = "WebService.Ports.http";.  Any suggestions?

    I gave up, uninstalled VUM server, re-installed on the vCenter server administrator, used 127.0.0.1 and VUM finally got with valid SSL certificates.  As part our design, we didn't have the same server as vCenter VUM but I found myself with no other choice.

  • I get a certificate warning expired only on one of my computers before going on a Web site

    Can someone help me with this problem.  I go to the site even on other computers right newspaper with without giving computer only problem me certificate expired message warning Web site.

    Hi metra621,

    1. Once you get this error message?

    2. What is the full error message?

    3 are you facing this problem with a particular application?

    4. you remember to make changes to the computer?

    Post with the required information so that we can help you better.

    If you are facing this problem with Internet Explorer, then I suggest you to take a look at the following link and check if it helps:

    About certificate errors

  • No certificate available for iPad distribution

    I am an educator with an iOS University developer account, which does not create Distribution certificates. Adobe App Builder doesn't let me continue to create the application without the certificate. Is it possible to test the app on my iPad without the App Builder?

    To use DPS App Builder to create an application, you must specify a cert of development as a CERT Distribution. trying to contact someone in your group of COMPUTER on obtaining the certificate of Distribution, even if you don't plan to use it. Without certificates, you can use Adobe Content Viewer to view your folios, but you can't build an application from development to testing.

Maybe you are looking for