SSL Automation tool fails to assign new Certs

Hey all,.

I'm having a puzzling problem... Let me to you the basics of the road...

I use 2 ESXi hosts on version 5.1.

I installed vCenter on a virtual machine hosted on Windows server 2008 R2...

I ran the method of simple installation using SQL 2008 express, the server is largely autonomous.

VCenter, connected as [email protected], configured services successfully installed the connection so that domain administrator account and set this area as main.

I am able to connect successfully as a domain administrator, but cannot configure vCenter server as it said that none was found, so I had to sign in again with the admin of vsphere and enable permissions on the server vCenter object domain admins.

All good finally created my store of data, Cluster, and all added hosts fine...

Now, I wanted to finally get to the point where I wanted to certifcates signed by our CA company, so I don't have to worry about the validity of the CERT whenever I connect.

VMware KB: Deployment and using the certificate SSL 1.0.x automation tool

After TONS of reading, I configured my Cert model in my company CA, arrived to form necessary must wait its SHA1 game and would recommend sha-256... but no matter, generate my req, get it signed, create a string of cert...

Now I'm finally on the attribution of the cert to the service...  (note that this tool is installed directly on the server vCenter Server, c:\VMware dir)

Press 3 (updated SSO)

Press 1 (update the SSO Cert)

Enter all the required fields as planned with the full paths to the directory...

Then I get this! Error but below is extracted from the actual log file.

2014-08 - 05T 12: 05:56.741 - 0500 [c.v.s.c.r.RunBuilder] race INFO: reg query HKEY_LOCAL_MACHINE\SOFTWARE\VMware, Inc. \VMware Infrastructure\SSOServer / t REG_SZ /v InstallPath

2014-08 - 05T 12: 05:56.909 - 0500 [c.v.s.c.r.RunBuilder] out of State INFORMATION: 1

Now I open reg edit and navigate to that directory reg, but there is no such a key of 'InstallPath'... What I'm doing wrong!

Hello, Zewwy.

You should definitely use SSL Automation Tool 5.5 to your vCenter and its services (Web Client, inventory, etc...). On ESXi: I replaced the CERT of the host by my hands, and not by the tool.

Also, be sure to use SHA256RSA algorithm. Here are the instructions for ESXi VMware KB: configuration CA signed certificates for ESXi hosts 5.x .

Tags: VMware

Similar Questions

  • SSL automation tool does not load advanced configurations

    Hi all

    I'm trying to upload a new SSL certificate on my server vCenter (Virtual Center 5.1 u1b). I have already asked the certificate, create all necessary files and I am trying to load on my environment.

    My vCenter server have the same name of the certificate, we use an alias to make easier the connection of the workstation to VDI environment.

    That's my problem, when I try to add the new certificate that I received the message below:

    [.] ERROR: The leaf certificate has not any CN or subjectAltName that match

    are the public address of the current computer. The rejection of the chain. To ignore this

    check, set the environment variable 'ssl_tool_no_cert_san_check' to 1.

    [.] ERROR: The supplied certificate string is not valid.


    Okay, I went to the config file and published. I activated the ssl_tool_no_cert_san_check with the variable 1 and restart the tool.


    Soon the automation tool starts, you receive the following message:


    F:\SSLAutomationTool1.0.1 > ssl - updater.bat

    'ssl_tool_no_cert_san_check' is not recognized as an internal or external command

    d, operable program or batch file.


    If the parameter I need is not loaded.

    Anyone know how I can fix this?

    Thank you

    Hello Frank, I am not owner of the process of certificate creation.

    The company I work ask Symantec Verizon certificates and each aditional WHAT DNS is charged. While only one name is added to the certificate.

    In relation to the question, I added the line in bold below on file ssl - updater.bat

    : updateVC_SSL

    Set ssl_tool_no_cert_san_check = 1

    call: echoAndLog ' services which are delivered to market as part of this operation are: VMware VirtualCenter Server, VMware vSphere and VMware VirtualCenter Management Web services oriented Storage Service profile. "

    call "%~dp0tools\read-params.bat" - vc

    call: validateCertificateChainFully ' % vc_cert_chain: '% =' "% vc_private_key: «= %»»»

    Thank you

  • Error SSL Automation Tool

    I'm updating my certificates for certificates signed by our CA. When I update the SSO certificates, he asked my master password. When I get in there, it gives me an error that the password is incorrect. I know that it is correct, because I uninstall SSO with the same password and can change passwords for admin with the rsautil utility (which requires that the password). According to me, it gives me an error because I have an ampersand (&) my password and he treats as a delimiter.

    Since according to VMware, there is no way to change the SSO password, I'm SOL? If I have to uninstall and reinstall with a new password for SSO, which will ruin anything? All that I really care about is that my VDI clients are disconnected and it can reconnect to customers (all full clones).

    BTW, I already tried to change the password with this German site (http://translate.googleusercontent.com/translate_c?depth=1 & hl = in & rurl = translate.google.com & sl = of & tl = in & u = http: / / www.die-...)

    Have you tried running just

    rsautil manage the-secrets - a change

    It should automatically request the normal password and a new password by avoiding any command-line escaping issues.

  • SSL Cert automation tool

    Hello

    I wanted to vSphere update 5.1 to 5.5 and had problems with the standard certificates. So I decided to stop and first to replace now. We will generate certificates by our internal CA and spread with the SSL Cert automation tool.

    Read a few KBs I have two questions before you start.

    1. may I do the modification of certificates in production period or do I have to put something in maintenance mode and so I have to do this weekend?

    2. While the tool is running, I'm able to choose what services I want to update. When I choose "8" all services are selected. It doesn't matter if do not have all of them running. For example, we do not have the Orchestrator, but I don't know if we Log Browser.

    Thanks in advance

    Wolfgang

    Hi Wolfgang,.

    (1) you will need downtime that services are restarted a couple of times, also don't forget to close all dependent solutions (VMs should not affect but that managing the components are affected).

    (2) log browser is embedded in the Web Client, so if you have that installed you also Log browser

  • Download CC fails on a new PC with no previous installation

    Download CC fails on a new PC with no previous Setup - run the adobe CC cleaning tool and redownloaded according to the advice of the forum but still fails - error 43 - advice please

    Please follow the steps below:

    (1) uninstall Creative Cloud Desktop Manager:

    Using creative cloud | Uninstall the creative cloud desktop application

    (2) delete following folders: ( If you do not see any folder skip this step )

    C:\Program Files (x 86) \Common Files\Adobe\OOBE

    C:\Program Files (x 86) \Common Files\Adobe\Adobe Application Manager

    C:\Program Files (x 86) \Adobe\Creative Cloud files

    C:\Users\\AppData\Local\Adobe\ MAA UPDATER and OOBE ( App data & Program Data is hidden folder please see, Show files and folders hidden in Windows 7, 8.x, 10, or Vista)

    \Adobe\ DONNÉES C:\Program rename SL-STORE like SL-STORE_OLD

    3 - Click on the link below and download Creative Cloud Installer file and use them to install the creative Cloud Desktop application.

    Download Adobe Creative cloud apps | Free trial of Adobe CC

    Let us know if that helps.

  • 14 Photoshop. I'm trying to merge (do a panorama) 2 photos.  The 'automation tools are grayed out', which means that I can not select this option.

    I just upgraded from photoshop 10 to 14. I'm trying to merge (do a panorama) 2 photos.  It was very fast and easy in Photoshop 10.  In photoshop 14 the 'automation tools are grayed out', which means that I can not select this option.  I do something wrong or my installation does not work?

    In the 14 PES Editor, adobe has moved the Photomerge features to guided.

    Photoshop elements help | What's new in Photoshop elements 14

    Photoshop elements help | Guided - mode Photomerge edits

  • Unable to connect to the VMware Research Service - the SSL certificate verification failed

    Hello world

    to implement the new vCSA 5.1 but I get an error when you try to connect via browser Web Client.

    "Impossible to connect to the VMware Research Service . https://xxx.xxx.xxx.xxx:7444/lookupservice/sdk - The SSL certificate check failed. »

    I've found this KB

    http://KB.VMware.com/selfservice/search.do?cmd=displayKC & docType = kc & externalId = 2033338 & sliceId = 1 & docTypeID = DT_KB_1_1 & dialogID = 423540040 & StateID = 1% 200% 20423538503

    The manual/work around seems to be a lot of work for me and perhaps this will cause other problems in the service due to problems of certification :/

    I also think that this cannot be the solution for a whole new vCSAppliance...-_-

    I am also able to go to https://xxx.xxx.xxx.xxx:9443 / admin-app

    is it correct for the device?

    You need to regenerate the certificate for Server Appliance after change of IP/hostname.

    Visit this link: http://www.virtual-blog.com/2012/09/failed-to-connect-to-vmware-lookup-service/

    Also, the admin/management interface is https://: 5480

    Lack of credentials [root/vmware]

    HTH

  • Apple DEP - automatically assigns new devices

    as indicated in article https://help.apple.com/deployment/business/?lang=en-gb#/tes54ab8fff2, when you change a MDM server on deploy.apple.com, there should be an option to automatically select "assign new devices" - this seems however not that is the case I don't forget anything?

    Salling PB

    To after my experience with that of in your MDM solution. May be a typo?

  • VMWare Tools fails in Ubuntu guest OS for the invalid kernel headers

    Installation and configuration of VMWare Tools fails in my Ubuntu OS prompt, because it cannot find a valid kernel header place, seems...

    I have build and headers packages installed:

    $ sudo apt - get install linux-headers-$(uname-r)

    Reading package lists... Fact

    Building dependency tree

    Reading state information... Fact

    Linux-headers - 3.16.0 - 60-generic is already the latest version.

    0 updated, 0 newly installed, 0 to remove and 3 not upgraded.

    $ uname-a

    Linux ubuntu 3.16.0 - 60-generic #80 ~ 14.04.1 - Ubuntu SMP Wed Jan 20 13:37:48 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux

    $ ls-l/usr/src

    Total 32

    drwxr-xr-x 24 root root 4096 24 feb 10:20 linux-headers - 3.13.0 - 79

    drwxr-xr-x 7 root root 4096 24 feb 10:20 linux-headers - 3.13.0 - 79-generic

    drwxr-xr-x 24 root root 4096 mar 17 2015 linux-headers - 3.16.0 - 30

    drwxr-xr-x 7 root root 4096 mar 17 2015 linux-headers - 3.16.0 - 30-generic

    24 drwxr-xr-x root root 4096 28 gen 18:59 linux-headers - 3.16.0 - 57

    drwxr-xr-x 7 root root 4096 28 gen 18:59 linux-headers - 3.16.0 - 57-generic

    drwxr-xr-x 24 root root 4096 Feb 8 18:10 linux-headers - 3.16.0 - 60

    drwxr-xr-x 7 root root 4096 February 24 10:27 linux-headers - 3.16.0 - 60-generic

    Debugging a bit vmware-config - tools.pl, I managed to limit the matter until this fault of command:

    $ sudo/usr/lib/vmware-tools/sbin64/vmware-modconfig-console - vmxnet 3.16.0 - 60-generic build-mod - k ' / usr/bin/gcc ' ' / usr/src/linux-headers-3.16.0-60-generic/include' misc vmxnet - l ' / usr/lib/vmware-tools ".


    As much information from the kernel will not work with the running kernel
    .

    Anyone with a clue of this error?

    Thank you!

    I downloaded and installed the VMWare Tools 10.0.0 and installed - I have no problem now, and I can see the shared folder correctly under the/mnt/hgfs, as expected...

    Thank you all!

  • Running Adobe cs5 on my desktop and laptop. The desktop hard drive has failed. A new hard drive was installed. I reinstalled Adobe cs5, but I can't update.

    Running Adobe cs5 on my desktop and laptop. The desktop hard drive has failed. A new hard drive was installed. I reinstalled Adobe cs5, but I can't update.

    Try direct updates

    https://www.Adobe.com/downloads/updates/

  • How do I reselect the type to change.  I have a text template that I want to, but when I try to select it with the text tool always creates a new text layer.  How to change the type of the layer in my registered design?

    How do I reselect the type to change.  I have a text template that I want to, but when I try to select it with the text tool always creates a new text layer.  How to change the type of the layer in my registered design?

    OK, Bob. This give a try.

    First, open a new file and make sure the background is white, not on Transparent that I suspect you have currently defined.

    Then, type your copy. Your layers panel will then look like the top of this picture...:

    and when you drag the text on the image layer, it will look like the lower part of the sample above.

    You can then position the text layer with the tool move

  • Text tool fails in the last Muse CC update

    My second huge glitch discovered in Muse was last updated. Type tool fails. Trying to change a text, the text tool only we will make you a text box. The tool is stuck and won't allow changes in an existing text box.

    The program is now unusable. Complete failure. Don't know what to do. Sickening sensation know Adobe only collect information. Never actually helps fixed a glitch in the program.

    What to do. Uninstall

    Anyone?

    Paul Russell

    theknottedbranch,

    Since a slideshow is a multifaceted, try selecting the text box itself with your black arrow, and once it is selected, using the text tool to change the text on the page.

    I hope this helps!

  • Publish the application fails for our new show.

    Publish the application fails for our new show. What is the problem of service or subscription? How will I know?

    Thank you.

    He was neither.

    Reconstruction of the folio and the Uploader again solved my problem.

  • AAPT tool failed

    SDK: AIR 14.0.0.110

    Project for android. Tie the lifetime, I got these errors:

    AAPT tool failed: C:\Users\king\AppData\Local\Temp\7fb6690a-7704-4500-9a20-b9c9a4797026\captive_runt ime_res\layout\wand_companion.xml:7: error: error: no found resource that corresponds to the name (at the "bottom" with the value ' @color/transparent').

    C:\Users\king\AppData\Local\Temp\7fb6690a-7704-4500-9a20-b9c9a4797026\captive_runtime_res\ layout\wand_default.xml:8: error: error: no found resource that corresponds to the name (at the "bottom" with the value ' @color/transparent').

    C:\Users\king\AppData\Local\Temp\7fb6690a-7704-4500-9a20-b9c9a4797026\captive_runtime_res\ layout\wand_default.xml:8: error: error: no found resource that matches the first name ("textColor" with the value "@color/white").

    C:\Users\king\AppData\Local\Temp\7fb6690a-7704-4500-9a20-b9c9a4797026\captive_runtime_res\ layout\wand_default.xml:8: error: error: no found resource that matches the first name ("text" with the value "@string/air_wand").

    C:\Users\king\AppData\Local\Temp\7fb6690a-7704-4500-9a20-b9c9a4797026\captive_runtime_res\ layout\wand_default.xml:19: error: error: no found resource that corresponds to the name (at the "bottom" with the value ' @color/transparent').

    C:\Users\king\AppData\Local\Temp\7fb6690a-7704-4500-9a20-b9c9a4797026\captive_runtime_res\ layout\wand_default.xml:19: error: error: no found resource that matches the first name ("textColor" with the value "@color/white").

    C:\Users\king\AppData\Local\Temp\7fb6690a-7704-4500-9a20-b9c9a4797026\captive_runtime_res\ layout\wand_default.xml:32: error: error: no found resource that corresponds to the name (at the "bottom" with the value ' @color/transparent').

    C:\Users\king\AppData\Local\Temp\7fb6690a-7704-4500-9a20-b9c9a4797026\captive_runtime_res\ layout\wand_default.xml:40: error: error: no found resource that corresponds to the name (at the "bottom" with the value ' @color/transparent').

    C:\Users\king\AppData\Local\Temp\7fb6690a-7704-4500-9a20-b9c9a4797026\captive_runtime_res\ layout\wand_default.xml:40: error: error: no found resource that matches the first name ("textColor" with the value "@color/white").

    C:\Users\king\AppData\Local\Temp\7fb6690a-7704-4500-9a20-b9c9a4797026\captive_runtime_res\ layout\wand_default.xml:53: error: error: no found resource that corresponds to the name (at the "bottom" with the value ' @color/transparent').

    C:\Users\king\AppData\Local\Temp\7fb6690a-7704-4500-9a20-b9c9a4797026\captive_runtime_res\ layout\wand_default.xml:53: error: error: no found resource that matches the first name ("textColor" with the value "@color/white").

    What's wrong?

    Hello

    Thank you for reporting the problem, the same problem is discussed here - https://forums.adobe.com/message/6446565#6446565

    Hope that helps.

    -Thank you

    Pahup

  • "The initiallization SSL during connection failed." Error

    Hello:

    We just to install a global certificate in our server VMware View connection and now remote ThinApp VMware clients and web clients do not work.  With ThinApp, successfully view customer, he meets with the connection to the server and authenticates the user, but when he tries to establish a tunnel connection, it fails with the error "authentication failure of the server to connect to the view.  Initialization of SSL when connecting to the server ""https://a.b.c:443' failed. " "

    Is certainly not a problem to solve.  When the name cannot be resolved by the customer, the error message reads "the view connection server authentication failed.  The server name "http://a.b.c:443' could not be resolved..." »

    I also confirmed this with packet sniffing.  The client opens a connection on port 443 on the server view connection and then appears to reject the certificate of the server.  (A TLS notify and close alert is sent by the client.)  When you connect for authentication instead of establishing the tunnel, there is no problem.

    I wonder if the fact that the certificate is a certificate with wildcards may contribute to this question.  For example the portion of tunnel of the customer have been written using another SSL/TLS library as part maybe authentication would result questions.

    The most confusing part of this question, is that ThinApp client is agree with the certificate on the local network (these are different machines).

    Any other advice would be appreciated.

    Thank you!

    Update: in the application logs customer, the tracking error.

    SSL: ClientHandshake: InitializeSecurityContext FAILED, Error 0 x 80090308 (the token supplied to the function is invalid).

    The exact same ThinApped View Client does not generate this message on the machines on the local network.  Unfortunately, I can't try to attach a remote computer to the local network to test because of politics.

    Post edited by: njlaw

    Not sure if this will help or not, but I thought I'd throw it out there.   About two months ago, I was working with a customer who had some strange issues SSL conecting in our view eviroment.   They were running a proxy server, so we focused on it and after a few days, I opened a ticket of VMware.   Very quickly, I received a temporary customer who solved the problem of our customers.  When I asked for more details it gave me the info below.  If you use a proxy, this could be it.  My SR number has been 1524766561 if you need to reference it.

    "The problem occurs when a given frame of"token"or SSL data exceeds the size of a single TCP read, which requires so a second reading to complete the token. What causes the second reading data to replace the first reading, rather than add. When this happens, the Windows Client to view SSL handshake failure reports.

    This problem may also occur if you use your own server certificate SSL has Extended Validation (which makes the bigger than the VMware View supplied self-signed certificate certificate) and go through a proxy server (which may change the TCP characteristics like the size packages). »

    If you have found this device or any other useful post please consider the use of buttons useful/correct to award points

Maybe you are looking for

  • Re: Question on Satellite P300-18Z

    Hi all I have a few questions on the Satellite P300-18Z. What "video output" this laptop have? (DVI, s-video or d - sub)Can I connect the laptop to a LCD - TV screen and watch movies on 1080 p resolution? (full-HD)What is the warranty on this laptop?

  • Cannot connect Tecra 9000 to wireless network

    Hello I am trying to connect my laptop Toshiba T9000 to my BT home Hub 2.0 Wireless v but a little difficulty.The laptop recognizes the hub, but every time I click on connect, I get the same message. ""Windows cannot connect to the selected network.

  • video cards

    Hi my hp desktop computer is a HP Pavilion p7 - 1007c and I want to upgrade my video card on an ASUS HD7850-DC2-2GD5 but the thing that is on requirements it say pci Express x 16 3.0 and I want to know if he's going to be compatible with my descktop

  • T530 The bad memory

    My T530 (i7-3720QM, 2.6 GHz, 4 GB) is 18 months old. Lately, some programs acted weird (region of a window will be unclear). Lenovo Solutions HW audit found nothing wrong. I decided to run Memtest86 + (v5.01) to check the memory and it has detected a

  • Where can I download the Vista Version of Movie Maker (6.0 NOT 2.6)?

    I have Windows 7, but my version of Movie Maker does not allow me to edit. MPG files. Where can I download Windows Movie Maker 6.0? Please don't give me a link to download 2.6 cause I tried this and it's slow and I like the Vista version much better.