Replace the certificate SSL of Insight Log with a CA signed cert

I'm trying to generate a cert for Insight Log using the method described in this blog post (below) using an automated batch file

http://www.derekseaman.com/2012/09/VMware-vCenter-51-installation-part-2.html

The chain.pem file resulting includes my cert and chain cert CA.  When I try to add to the Insight Journal, it is said that the cert is invalid.  Is that you guys can provide suggestions on how to change this piece of lot code to use Log Insight?  The meat of the lot is listed below (I just left aside all the variables that are defined in advance)

CD /d %Cert_Path%\loginsight

% OpenSSL_BIN % genrsa 2048 > rui.key

% OpenSSL_BIN % req-out rui.csr - rui.key - new config key - loginsight.cfg

Certreq-submit - q - f config "% nom_autorite_de_certification %" attrib-"CertificateTemplate: % Cert_Template % ' rui.csr rui.crt

% OpenSSL_BIN % pkcs12-export - in rui.crt - inkey rui.key - certfile % CA_Cert_Chain % - name rui-out rui.pem

copy/b rui.crt + % CA_Cert_Chain % chain.pem

You must have a file that contains the key and the string, otherwise you will get an error. This command:

% OpenSSL_BIN % pkcs12-export - in rui.crt - inkey rui.key - certfile % CA_Cert_Chain % - name rui-out rui.pem

Creates a file, but rui.pem is incorrect. It is actually creating a rui.pfx (see at the bottom of this link: The Most Common orders OpenSSL). I think the problem is that you have the - flag of knots at the end of the command (see what is the purpose - nodes in the openssl argument? - Stack Overflow). A visual way to check is to open the .pem and ensure one contains a section – BEGIN RSA PRIVATE KEY. The chain.pem does not work and the rui.pem is binary, because these two will fail. I hope this helps!

Tags: VMware

Similar Questions

  • Error replace the certificate SSL - inventory services with using SSL - please help automation tools

    I uses updated SSL tools to change the SSL to vCenter 5.5 certificate.

    Modification of SINGLE authentication certificate has been successful, but I'm having a problem with the inventory services.

    Error message below.

    ==================================================================

    4 update the inventory Service SSL certificate

    1. update the confidence of the inventory of Single Sign-On Service

    2. update the Service of Trust inventory to vCenter Server

    3 update the inventory Service SSL certificate

    4. back to the old inventory SSL Certificate Service

    5. return to the main menu to update other services

    The service chosen is: 3

    [Wednesday 3 December, 2014 - 13:49:12.88]: services that are delivered to market as part of thi

    operation s are: vCenter Inventory Service.

    Enter the location of the new inventory channel Service SSL: C:\certs\InventorySer

    vice\chain.PEM

    Enter the location of the new private key for the inventory Service: C:\certs\InventoryS

    ervice\rui - orig.key

    Enter the SSO administrator user (default value is: administrator@vsp)

    here.local):

    Enter the SSO administrator password (not displayed):

    [.] The supplied certificate string is valid.

    [Wednesday 3 December, 2014 - 13:49:44.41]: last update of functioning inventory Service SSL cert

    ificatsanitai re has failed:

    [Wednesday 3 December, 2014 - 13:49:44.42]: unable to determine if the inventory Service is registe

    Red with Single Sign-On - errorlevel is 1

    =================================================================

    Problem solved, as the vCenter my share of the same SSO domain environment is necessaio that certificcado the backend SSL is changed.

  • How do I configure the iPad2 to synchronize the iPad-Mailclient with Exchange 2010 via Active Sync using the certificate SSL client and name of user and password?

    Active Sync iPad ssl Client certificate

    How do I configure the iPad2 to synchronize the iPad-Mailclient with Exchange 2010 via Active Sync using the certificate SSL client and name of user and password?

    Hi Ewoki,

    Your question is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the TechNet Exchange forum. Please post your question in the Forums TechNet in Exchange Server.

  • Replacement of Certificate SSL - invalid certificate format

    Has anyone had luck replacing the default SSL certificate?  I have a cert .pem format with the string to it and is having back and error of invalid certificate format.  I tried out the string just to see and who did not, but it gives me good to go, because I believe that we meet all the requirements of the cert.  Y at - it logs that would provide more info on the issue?

    Have you checked: replace the newspaper Insight SSL certificate with a CA signed cert

  • I need to replace the bookmarks on my 2nd computer with those of my main computer.

    Original title: replace bookmarks

    I need to replace the bookmarks on my 2nd computer with those of my main computer.  How can I remove those on the 2nd without having to remove a folder at a time.  If I don't have and I install the bookmarks of the computer main I get two sets of records on computer 2.

    Don Jacobs

    Thank you for your resjponse.  Sorry about the omission of browser.  I use IE 8.  I don't know about the sequence of import and export.  I need to know, what I can erase the bookmark.htm file before I import without which performs the import just puts a second series of folders on the laptop...

    Don. I guess that I'm missing something here because I do not understand what it is you are trying to say.

    First of all, let's say that computer 1 to the desired favorites. Computer 2 is where you add the Favorites. Go to the computer 1 and save (export) your Favorites. Go to computer 2. Remove all Favorites (C:\Users\Owner\Favorites.. Please be advised that your path may vary). Now on computer 2, click on the ' import '. Navigate to the file htm to computer 1. Your Favorites from computer 1 are now in place.

  • I just replaced the hard drive in my PC with my arrival of the damaged disc. I'm wondering now "activate Windows now".

    I just replaced the hard drive in my PC with my arrival of the damaged disc. I'm wondering now "activate Windows now". The code on the computer case was partly carried away and I do not have a record of it. The software has been activated once already. Suggestions, please.

    original title: hard drive swap.

    Use a magnifying glass and a strong light and see if you can retrieve the key.  It is not registered anywhere except on the label.  They are applied at the factory in batches, and there is no record that the key is affixed to a specific computer.  Recover what you can and then try to activate by phone.

    To activate Windows Vista by phone, follow these steps: click Start, and then click computer.  Click System Properties on the toolbar, and then click click here to activate Windows now in the Windows activation area.

    If you are prompted for an administrator password or a confirmation, type the password, or click on continue.  The Windows of Activation Wizard starts.  Click use the telephone system automated in the Windows Wizard of Activation.

  • Replace the hard drive of 500 GB with 256GB SSD in spectrum XT Touchsmart

    I tried to replace the HARD drive of 500 GB with 256 GB Samsung SSD and then began to install it using the external DVD drive, but during installation without disk hard were found. What I have to disable certain BIOS settings or I need to install the SSD in a separate location. Any kind of help is greatly appreciated.

    Yupp, I could install an SSD. You need to install the drivers for RAID Intel® Rapid Storage Technology (Intel® RST) driver (https://downloadcenter.intel.com/Detail_Desc.aspx?agr=Y&ProdId=2101&DwnldID=22194&ProductFamily=Software+Products&ProductLine=Chipset+Software&ProductProduct=Intel%C2%AE+Rapid+Storage+Technology+ (Intel % C2% AE + RST) & lang = fre) during the installation of Windows 8. I extracted the drivers for USB and everything by choosing which device to install windows 8 installed drivers.

    After that, the SSD has been detected and the simple installation procedure. I pasted the link for the driver, don't know whether or not it will get removed. In case it is removed just search driver RAID Intel® Rapid Storage Technology (Intel® RST).

  • Can I replace the CC of InDesign, I bought with a CS6 version? My system is not compatible with InDesign CC.

    Can I replace the CC of InDesign, I bought with a CS6 version? My system is not compatible with InDesign CC, I would download InDesign CS6 instead.

    Two options

    Previous through Cloud http://helpx.adobe.com/creative-cloud/help/install-apps.html#previous

    - and the difference in the Cloud application manager 2015 https://forums.adobe.com/thread/1906752

    Buy the serial number Creative Suite 6 version that does not use the cloud

  • Replace the carriage return or new line with a table space

    Hello

    I want to replace the carriage return or new line with space in my column of the database.

    To do this, I'm using this query:

    Select replace (replace (Comments, chr (10),' '), Chr (13),' ') OF Comments_Master

    Comments_Master is the name of the table and comments is column that contains carriage return or new line.

    But this query works as expected.

    Once I run this query and run the query again "select * FROM Comments_Master", transport return and new line still exist.

    Please let me know what is wrong with this query?

    You write that data back you? This example shows that your sql should work. I thinnk the query that you just described is the updated one below.

    create table blah (text varchar2 (100));

    insert into bla values (' it's multi)

    line of text ");"

    Select * from blah.

    Select replace (replace (text, chr (10),' '), Chr (13),' ') of bla.

    Update text bla = replace (replace (text, chr (10),' '), Chr (13),' ');

    Select * from blah.

  • Trying to follow KB: 2118939 - replace the Service SSL certificate research on a platform of Services controller 6.0 - ls_update_certs.py - FAILURE

    EDIT: Posted KB poorly in the subject line and below (KB fixed the link shown below, was not able to change the field of the object above).

    I try to follow KB 2109074 - VMware KB: vCenter server certificate validation error or a service platform for the VMware Solutions external... controller

    My steps relate to the 2 k linked to in the main article: 2109074

    Everything went very well in order to run the final order as get the old footprint certificate, obtain the new certificate file, etc..

    When you try to run the actual command in Windows (tmore successful version that it the command I am running as follows):


    "C:\Program Files\VMware\vCenter Server\python\python.exe" ls_update_certs.py - url https://vcenter.domain.local/lookupservice/sdk -fingerprints b1:35:c1:9 c: a5:59:dd:ab:3d:c2:50:e7:92:79:82:f0:b6:85:7 d: c8 - FichierCert C:\certificates\ [email protected]' user password ' Passw0rd & '

    BTW, the VMware KB says:

    "Note: on Windows systems, place the password in double quotes."

    I have this error is (fgarlic on get-site-id):

    ----------------------------------------------------------------------------------------------------------

    Traceback (most recent call changed):

    File "ls_update_certs.py", line 19, < module >

    args. Password)

    File "C:\Program Files\VMware\vCenter Server\VMware identity Services\lstool\s

    cripts\lstoolutil.py', line 79, modify_svc_ep_certs

    raise exception ("'get-site-id lstool' failed: %d"% rc ')

    Exception: "lstool get-site-id" failed: 1

    ----------------------------------------------------------------------------------------------------------

    I tried this on 2 different vCenter servers (both 6.0u2) and get the same behavior, I have tried every combo of passwords for the PSC/SSO as Passw0rd.   Pass-w0rd P@ssw0rd W34df * fdc4... etc and tried with or without quotes (2 citations, 4 citations), tried bash escape after the password like:-... and nothing works. I do not know if it is a problem of password. A few lines above I see things showing this:

    ----------------------------------------------------------------------------------------------------------

    Caused by: com.vmware.vim.vmomi.core.exception.CertificateValidationException: Sserver certificate chain not verified

    Caused by: javax.net.ssl.SSLPeerUnverifiedException: peer not authenticated at sun.security.ssl.SSLSessionImpl.getPeerCertificates (SSLSessionImpl.jagoes: 421) to com.vmware.vim.vmomi.client.http.impl.ThumbprintTrustManager$ Hostname Verifier.verify (ThumbprintTrustManager.java:296)

    ----------------------------------------------------------------------------------------------------------

    However, I can run this command (which does not require a password) successfully:

    "C:\Program Files\VMware\vCenter Server\python\python.exe" 'C:\Program Files\VMware\vCenter Server\VMware identity Services\lstool\scripts\lstool.py' get-site-id - url https://vcenter.domain.local/lookupservice/sdk" " " " "

    .. It works very well and shows the SSO sso-site-default name.

    Has he's other aspects of the signed certificate installation succeeded except the Search Service of that is causing my NSX Manager install to connect do not back up the Search Service...


    I also get the error on the Web Client showing this:

    "Error during processing of the application. Check logs WebClient vSphere for more details".     (Refer to KB: https://kb.vmware.com/kb/2129053 ) ).. .caused by the same issue as well:



    Anyone see this problem or knows anyway possible to recover from it without having to re - install? How to debug the .py scripts better? Is there a better documentation of VMware on the operation of these scripts? If the Search Service can be re-installed?


    Any help is greatly appreciated!

    Ahhhh-hah... I found the problem.

    If I manually run the command:

    ""C:\Program Files\VMware\vCenter Server\python\python.exe"'C:\Program Files\VMware\vCenter Server\VMware identity Services\lstool\scripts\lstool.py' list - url https://vcenter.domain.local/lookupservice/sdk"

    Can I get good output... The command works great.

    But just as a hunch, I had to check something, I decided to see what happens when I run the same command with the '-non-cocher-cert' put it as as follows:

    ""C:\Program Files\VMware\vCenter Server\python\python.exe"'C:\Program Files\VMware\vCenter Server\VMware identity Services\lstool\scripts\lstool.py' list - no-check-cert - url https://vcenter.domain.local/lookupservice/sdk"

    .. .and guess what? I got the SAME java error as in all the other scripts: "peer not authenticated."

    So I went to the folder of scripts for VMware lstool (C:\Program Files\VMware\vCenter Server\VMware identity Services\lstool\scripts\): open lstool.py with Notepad and see that he simply calls another script in the same folder called: lstoolutil.py

    I then opened that lstoolutil.py script in Notepad and did a search for the string:-non-cocher-cert... .and there has been 5 cases where different commands called this switch. I have placed in the comment (#) 5 lines composing this switch, saved the file and re-run the original script: ls_update_certs.py... .and WHAH-LABRIQUE Hooray!

    Line 52: # "-non-cocher-cert."

    Line 74: # "-non-cocher-cert."

    Line 85: # "-non-cocher-cert."

    Line 121: # "-non-cocher-cert."

    Line 139: # "-non-cocher-cert."

    "Then just to check I relaunch:"C:\Program Files\VMware\vCenter Server\python\python.exe"'C:\Program Files\VMware\vCenter Server\VMware identity Services\lstool\scripts\lstool.py' list - url https://vcenter.domain.local/lookupservice/sdk"

    .. and can confirm that all records of service have the field "SSL trust" with the new certificate key.

    Problem solved... That just leaves one a review to follow in case they encounter the same problem...

  • 2000-2d01SV HP: replace the hard drive in slim 7mm with 9.5 mm

    Can someone tell me if I can replace the hard drive from HGST thin 7mm supplied with my notebook HP 2000 - 2d01SV with a new 9.5 mm one?

    Note to the reader in this laptop is held in by a rubber drive support and not mounting screws.

    Thanks in advance.

    Dimitri

    Hello

    Yes, your laptop supports 6.35 cm (2.5 in.) 9.5 mm hard disks (. 37-in) and 7.0 mm (. 28 - in.) thick. A piece of rubber is 7mm thick.

    More information:

    http://h10032.www1.HP.com/CTG/manual/c03763129.PDF

    Kind regards.

  • I need to replace the HD on a p7-1206 with a SSD

    I need to replace the hard drive 2 TB system in a p7-1206 Pavilion with a 120 GB SSD. What is the best procedure to transfer the Win 7 OS to much smaller SSD? I created the set of recovery disks. After the start of recovery disks to install the OS on the SSD an error message said that capacity SSD was below the disk original and interrupted the installation process. Do I need a procedure which will reproduce all 4 partitions on the SSD drive in running or some partitions can be ignored?

    Thanks for your help.

    MusicCity wrote:

    ...  Do I need a procedure which will reproduce all 4 partitions on the SSD drive in running or some partitions can be ignored?

    Thanks for your help.

    Hello

    No, it also won't work. I hope that the following tutorial helps:

    http://www.overclockers.com/forums/showthread.php?t=670079

    Kind regards.

  • Authentication of the certificate SSL VPN

    Hello

    I change SSL VPN of aaa aaa authentication and CERT, Server 08 CA, 8.2 ASA 5510 ssl client 2.5.1025 and Windows 7 users. My question is what should be the model for the cert id I get from CA.

    Thank you

    Marie Laure

    You can use a web server for the certificate for the ASA model.

    Thank you

    Tarik Admani
    * Please note the useful messages *.

  • Replace the certificate self-signed prominent 5.3

    Select a certificate:

    1 Subject: C = US, S = CA, L = CA, O = VMware Inc., unit of ORGANIZATION = VMware Inc., CN = VVVDCVDID03, [email protected]
    Valid from: 31/12/2013-15:56:35
    Valid until the: 31/12/2015-15:56:35
    Footprint: E93EDE1797C55BC61E95DF625AC33EC8D30DD089

    2 object: CN = .net, OR default certificate of VMware View = VVVDCVDID03.mydomain, O = "VMware, Inc.."
    Valid from: 12/30/2013 15:24:20
    Valid until the: 28/12/2023-15:24:20
    Footprint: 671E847CA3A55FC31AA62034174B29EC37D4DF38

    3 object: CN = * .mydomain .net, O is my company Holdings LLC, L = Grant Park, S = Illinois, C = US
    Valid from: 01/08/2014-19:00
    Valid until the: 14/01/2015-07:00
    Footprint: 1D976E97E9B9C55A02470F45618F7E2CD8763B43

    Enter the choice (0-3, 0 to abort): 3
    Remove the link to certificate successfully 18443 port.
    Bind the new certificate to the port.
    ReplaceCertificate successful operation.

    Yet the certificate still shows as invalid and self-signed view Admin and when I join on the site.  It's showing that ranked #2 in the SVICONFIG.

    In addition to this SVICONFIG does not appear to be installed facing the connection to the server at the point 5.3. Or at least I can't.  5.3 documents do not appear to exist. 5.2 only.

    How can I replace the self-signed certificate in my servers connection and security now?

    http://pubs.VMware.com/view-51/index.jsp?topic=%2Fcom.VMware.view.installation.doc%2FGUID-5ED2A8AB-0D5F-495F-B2F7-D7C64C7A021E.html

    http://pubs.VMware.com/view-51/index.jsp?topic=%2Fcom.VMware.view.installation.doc%2FGUID-5ED2A8AB-0D5F-495F-B2F7-D7C64C7A021E.html

    The solution in the end was that the self singing and new cert had the same friendly name of "vrm".  Changed the name of the car to "oldcert" sign and restarted the server connection.  That solved.

  • When I open Firefox a video of two girls shopping and a guy on a phone replace the icon until I have stop with the Task Manager. A normal icon returns when it reopened. .

    When I open the Firefox browser a normal icon appears for a few moments and then is replaced by a link to a video. When I played the video it shows two young women shopping and a young man talking on his cell phone comes and seems to describe the choice of girls at the shopping to someone on the phone. The girls look concerned, and the message seems to be something about privacy. It is a bit odd and ends abruptly. Initially, I assumed the video was published by Firefox, but I'm not sure. It has been on my computer for months. Sometimes I can go to Firefox and see a normal homepage, but usually, that is quickly replaced by this. If I go on Manager tasks and 'end task' to Firefox, I can then open the Firefox browser and it will be normal with just the icon of Firefox and no link to the video.

    What does that mean? This video is supposed to be on my Firefox browser?

    Mozilla rotating exhibitions of excerpts on the topic: home page to run regularly for various campaigns and these changes.
    You might want to set a different page than the home page.

    If you prefer not to see excerpts on the topic: home page or if there are problems with a snippet of code, you can set this pref to a value of empty string on the topic: config page by removing the current value through the context menu (change) or a double click.

    • topic: config page: browser.aboutHomeSnippets.updateUrl (current value to delete)

    Delete the storage\persistent\moz-safe-about + House in the closed Firefox with Firefox profile folder (Firefox '3-bar' menu button > exit/Quit) remove code snippets stored in IndexedDB and make Firefox to use a default extract value.

    You can reset the pref browser.aboutHomeSnippets.updateUrl through the context menu on the default to reactivate the code snippets and make Firefox recreate the moz-trunk-fort-about + folder.

    Close and restart Firefox after changing the value of the preference of browser.aboutHomeSnippets.updateUrl.

    You can open the topic: config page via the address bar.
    You can accept the warning and click on "I'll be careful" to continue.

    You can use this button to go to the Firefox profile folder currently in use:

Maybe you are looking for

  • I can't create the custom toolbar

    Whenever I try to create the custom toolbar, it disappears after you restart Firefox. Can you suggest me a solution for this? Thank you!

  • HP Envy 4500: Cannot print with the new Wifi

    I have a new Netgear09 router and everything connected correctly. My HP Envy 4500 wireless printer has been a success with the wizard, and I printed out the specs very well. My computer (Windows Vista) is connected to the Internet fine... but when I

  • How do I export Notes to my iPod Touch?

    I looked at this question, and the most recent response is dated "2011". Please help me as far as possible. I want to be able to transfer/copy my notes from my iPod Touch to my MacbookPro, but if someone can tell me how to transfer to my computer Win

  • NOR-FBUS Configurator 4.1.0.49152 + USB-8486: High-delay between consecutive writing actions

    Hello Imagine a case where you have a block (transducer) at least about 12 parameters that both read and write access: PARAMETER_1 PARAMETRE_2 PARAMETRE_3 ... PARAMETER_12 PARAMETER_13 .... When editing two of these parameters which do not "resident

  • Windows XP KB976098 update

    I have the icon on the taskbar to install update. Click to update but fails to install. The update is for changes. (KB976098).How to install or remove?