VCenter Server 5.1 SSL certificate update - error

Hi all

We set up a new Windows 2008 R2 server as a vCenter Server 5.1

Now, I try to install the new certificates for all parts of vCenter (server, inventory, web client service,...) with the Windows certification authority.

I'm stuck at the update server certificate SSL vCenter with the 'Certificate SSL Automation Tool'.

This is part 5. in this guide (5. the cmd screen shot):

http://KB.VMware.com/selfservice/microsites/search.do?language=en_US & cmd = displayKC & externalId = 2041600 #updatestepsplanner

All credentials are correct, but I still get the same error (vc-update - ssl.log):

[26.04.2013 - 10:42:54, 99]: copy the new certificates and keys 'C:\ProgramData\VMware\VMware VirtualCenter\SSL. '... »
[26.04.2013 - 10:42:55: 00]: creating the PKCS certificate file...
Could not reload vCenter SSL certificates
[26.04.2013 - 10:42:56: 22]: ""cannot reload the server vCenter SSL certificates. " The certificate could not be unique. » »
[26.04.2013 - 10:42:56, 24]: new certificates and keys deleting...
[26.04.2013 - 10:42:56: 25]: restoration of the certificates and the original keys...
1 Datei () kopiert.
1 Datei () kopiert.
1 Datei () kopiert.
[26.04.2013 - 10:42:56: 25]: attempt to restore...
Could not reload vCenter SSL certificates
[26.04.2013 - 10:42:57, 08]: ""cannot reload the server vCenter SSL certificates. " The certificate could not be unique. » »
[26.04.2013 - 10:42:57: 10]: new certificates and keys deleting...
[26.04.2013 - 10:42:57: 10]: restoration of the certificates and the original keys...
1 Datei () kopiert.
1 Datei () kopiert.
1 Datei () kopiert.
[10: 42:57, 13 - 26.04.2013]: failure of the update of the certificate of vCenter.

So I tried the manual way, as it is mentioned in this guide:

I'm stuck here too, get a 'result of Method Invocation: vpx.fault.SecurityConfigFault ' after ""Invoke method ': "

  1. Go to https://localhost/mob/?moid=vpxd-securitymanager & vmodl = 1 on the server vCenter Server and load the certificates for the configuration using the managed object browser.
  2. Click continue if you are prompted with a warning on this certificate.
  3. Enter a vCenter Server administrator user name and password when prompted.
  4. Click reloadSslCertificate.
  5. Click the calling method. If successful, the window displays this message: result of Invocation of method: Sub.


I tried to fix this, but there is not really a solution for this:

http://communities.VMware.com/thread/429035

so, I need help with this question

SOLVED!

Steps to follow:

1. stop the vCenter service

2. search for your ID in LS_ServiceID.prop in the folder C:\ProgramData\VMware\VMware VirtualCenter

3. copy this ID (e.g. {C4672589-9258-42B1-90E2-1EF268BBD402}: 5 )

4. change your vpxd.cfg in the same folder and replace

vCenterService

with

your ID

5. start vCenter Service

Then, the SSL automation tool works!

You need to undo changes.

Tags: VMware

Similar Questions

  • The upgrade to vCenter Server to vCenter Server 5.1 5.1 update 1 when the SQL database is remote and vCenter Server Heartbeat is installed

    Hi guys,.

    I'm in the middle of an upgrade to vSphere 5.1 5.1 vSphere update 1. I have vCenter protected by HB and SQL on a separate computer (also protected by HB) I also run Syslog, Update Manager and Proxy authentication on vCenter.

    I've successfully upgraded HB on all 4 nodes (2 x vCenter & 2 x SQL) and started the upgrade components on the secondary according to the •vCenter Server Heartbeat 6.5 server and vCenter Update 1 Installation on Windows Server 2008 when the secondary server is virtual (PDF) http://www.vmware.com/pdf/vcenter-server-heartbeat-65-u1-installation-windows-2008-virtual-guide.pdf

    I got to step 3.c

    3. change the primary/active server role:

    a launch of the vCenter Server Heartbeat wizard configure server and click the tab of the Machine to change the server role for the current server (primary) to the active State and click Finish.

    b using the Service Control Manager, start the Server Heartbeat of VMware vCenter service.

    c using the vCenter Server Heartbeat Console, check that all the status icons on the server: summary page are green indicating that the boot process is completed and protected from all the services are started.

    d using the Service Control Manager, stop the service Server Heartbeat of VMware vCenter.

    As the vCenter service does not start, I'm stuck at this point. As far as I'm concerned, the error is quite logical. I've updated vCenter using the secondary server, and then I'm trying to connect (according to the guide) with another version that breaks down.

    If I continue with the services stop and launch the installer SSO, it is trying to perform an uninstall!

    Did I miss something in this upgrade?

    Concerning


    Ciaran

    Hi guys, VMware have finally updated the documentation to reflect the right way forward: https://www.vmware.com/support/pubs/heartbeat_pubs.html U1 6.5 Select from the menu drop-down and you'll see the last date of update for each of the documentation is now 10/10/2013. The guide States now specifically to restore the vCenter database before proceeding with any other measure, this is copied below for convenience: "the upgrade of the main server of the upgrade process further guess upgrading the secondary server completed successfully. Procedure 1 before continuing the upgrade process, perform a restore of the database of vCenter Server, Single Sign-On database, VMware Update Manager database and SSL certificates that were backed up in step 4 on the secondary server. regards Ciaran

  • vCenter Server Heartbeat v6.4 1 update necessary?

    The vCenter Server Hearbeat v6.4 Update 1 Release notes State twice:

    "If you have correctly installed vCenter Server Heartbeat v6.4, it is not required that you upgrade to vCenter Server Heartbeat v6.4 Update 1."

    Otherwise it is said to the news

    ' Support for vCenter Server 5.0 Update 1 -this version of VMware vCenter Server Heartbeat now supports of vCenter Server 5.0 Update 1.

    If anyone can clarify this? If I want to upgrade to vCenter Server 5 5 U1, I should improve Heartbeat of 6.4 to 6.4 U1 or not?

    Concerning

    Frank

    No, you don't need to upgrade. vCSHB 6.4 supports also vCenter 5.0 U1

  • Server 2008 R2 - 80070490 Windows update error

    I tried to install updates on my server and am getting error 80070490 several updates. An example is KB3000483

    I ran sfc/scannow - no problem

    DISM - returns

    Checking Windows Service Packages

    Checking of manifests package and catalogs
    (f) CBS MUM Corrupt 0 x 00000000 servicing\Packages\Microsoft-Windows-IE-Hyphenation-Parent-Package-English~31bf3856ad364e35~~~10.2.9200.16437.mum file name expected Microsoft-Windows-IE-Hyphenation-Parent-Package-English~31bf3856ad364e35~neutral~~10.2.9200.16437.mum does not match the name of the file
    (f) CBS MUM Corrupt 0 x 00000000 servicing\Packages\Microsoft-Windows-IE-Hyphenation-Parent-Package-English~31bf3856ad364e35~~~11.2.9412.0.mum file name expected Microsoft-Windows-IE-Hyphenation-Parent-Package-English~31bf3856ad364e35~neutral~~11.2.9412.0.mum does not match the name of the file
    (f) CBS MUM Corrupt 0 x 00000000 servicing\Packages\Microsoft-Windows-IE-Spelling-Parent-Package-English~31bf3856ad364e35~~~10.2.9200.16437.mum file name expected Microsoft-Windows-IE-Spelling-Parent-Package-English~31bf3856ad364e35~neutral~~10.2.9200.16437.mum does not match the name of the file
    (f) CBS MUM Corrupt 0 x 00000000 servicing\Packages\Microsoft-Windows-IE-Spelling-Parent-Package-English~31bf3856ad364e35~~~11.2.9412.0.mum file name expected Microsoft-Windows-IE-Spelling-Parent-Package-English~31bf3856ad364e35~neutral~~11.2.9412.0.mum does not match the name of the file

    Unavailable repair files:
    servicing\packages\Microsoft-Windows-IE-hyphenation-parent-package-English~31bf3856ad364e35~~~10.2.9200.16437.mum
    servicing\packages\Microsoft-Windows-IE-hyphenation-parent-package-English~31bf3856ad364e35~~~11.2.9412.0.mum
    servicing\packages\Microsoft-Windows-IE-spelling-parent-package-English~31bf3856ad364e35~~~10.2.9200.16437.mum
    servicing\packages\Microsoft-Windows-IE-spelling-parent-package-English~31bf3856ad364e35~~~11.2.9412.0.mum
    servicing\packages\Microsoft-Windows-IE-hyphenation-parent-package-English~31bf3856ad364e35~~~10.2.9200.16437.cat
    servicing\packages\Microsoft-Windows-IE-hyphenation-parent-package-English~31bf3856ad364e35~~~11.2.9412.0.cat
    servicing\packages\Microsoft-Windows-IE-spelling-parent-package-English~31bf3856ad364e35~~~10.2.9200.16437.cat
    servicing\packages\Microsoft-Windows-IE-spelling-parent-package-English~31bf3856ad364e35~~~11.2.9412.0.cat

    I tried to follow several suggestions on replacing these files, and cannot rename delinquency or files, but do not see how they relate to the question of application more or less of the KB, I can't find them anywhere to copy it from another computer or the Microsoft Web site.

    Suggestions on how to solve this problem?

    Please post your query to:

    https://social.technet.Microsoft.com/forums/

    Server issues are better addressed there.

  • vCenter Server Appliance and VMware Tools update

    I've just updated VCSA to 5.1.0.10000 build 1065184. I had to uninstall VMware Tools first because the update failed with

    "VMware Tools can not install because it seems that another installation of.

    VMware Tools is already present. Please remove the previous installation and

    then try again to install this version of VMware Tools. »

    error in /opt/vmware/var/log/vami/updatecli.log (I had a similar problem with the previous update).

    After updating, I see in this newspaper:

    "22/05/2013 14:43:48 [INFO] Running/opt/vmware/share/vami/vami_reconfigure_tools.

    VMware tools is not installed on this virtual machine.

    "22/05/2013 14:43:48 [INFO] status update: reconfiguration of done VMware tools.

    Should I install VMware Tools via vSphere Web Client again? I assumed VMware Tools to install update VCSA. I can see the packets in any case:

    VM-vcenter: ~ # rpm - qa | grep-i vmware-tools

    VMware-Tools-vmmemctl-KMP-default-1.2.1.2_3.0.13_0.27-3

    VMware-Tools-vmxnet-KMP-default-2.0.14.0_3.0.13_0.27-3

    VMware-tools-services - 9.0.5 - 1.sles11

    vmware-tools-plugins-hgfsServer-9.0.5-1.sles11

    VMware-Tools-plugins-VMBackup-9.0.5-1.SLES11

    VMware-Tools-VMCI-Common-9.0.5-1.SLES11

    VMware-Tools-vsock-KMP-default-9.3.3.0_3.0.13_0.27-3

    VMware-Tools-Libraries-NOx-9.0.5-1.SLES11

    VMware-Tools-vmmemctl-Common-9.0.1-3

    VMware-tools-core - 9.0.5 - 1.sles11

    vmware-tools-plugins-autoUpgrade-9.0.5-1.sles11

    vmware-tools-plugins-guestInfo-9.0.5-1.sles11

    vmware-tools-plugins-powerOps-9.0.5-1.sles11

    VMware-Tools-plugins-VIX-9.0.5-1.SLES11

    VMware-Tools-ESX-kmods-default-9.0.5-1.SLES11

    VMware-Tools-vmxnet-Common-9.0.5-1.SLES11

    VMware-Tools-VMCI-KMP-default-9.3.18.0_3.0.13_0.27-3

    VMware-tools-guestlib - 9.0.5 - 1.sles11

    vmware-tools-plugins-deployPkg-9.0.5-1.sles11

    vmware-tools-plugins-timeSync-9.0.5-1.sles11

    VMware-Tools-ESX-NOx-9.0.5-1.SLES11

    VMware-Tools-vsock-Common-9.0.5-1.SLES11

    VMware-tools-Foundation - 9.0.5 - 1.sles11

    But I can not start the daemon:

    VM-vcenter: ~ # /etc/init.d/vmware-tools-services start

    From an operating system daemon invited VMware Tools: failure

    After the assumption, I deleted/usr/lib/vmware-tools/lib / and was able to run vmware - install.pl and install VMware Tools 9.0.1.18551 (build 913578) then.

    I'm still confused why vmware-tools-services - 9.0.5 - 1.sles11 and other packages installed during the VCSA update did not work.

  • Where are the instructions for the upgrade to vCenter Server Appliance 5.0.0 updated 1 b to vCenter Server Appliance 5.1?

    I looked through the release notes and could not find an answer for this... the current ASB does not see the updates available to perform this move on the current instance of VSA... someone at - there more information on this?

    Check out http://kb.vmware.com/kb/2033990

  • vCenter 5.5 Virtual Appliance and SSL certificates

    I currently have vCenter 5.5 under Windows 2008 R2.  I've been thinking to replace my Windows with the appliance vCenter vCenter virtual.

    I have read the documentation on the SSL certificates for vCenter.  I bought a RapidSSL SSL certificate on my current server vCenter.  It seems that everything is working correctly, but the documentation I read says I need a different cert for various services such as inventory, Journal browser and AutoDeploy Service.

    VCenter requires there really that many different certificates?

    Yes, each component of vCenter server requires unique SSL certificate:

    Reference:http://www.vmware.com/files/pdf/techpaper/vsp_51_vcserver_esxi_certificates.pdf

    See also: http://pubs.vmware.com/vsphere-55/topic/com.vmware.ICbase/PDF/vsphere-esxi-vcenter-server-55-security-guide.pdf

  • Red vCenter - unable to check CA (PSC) signed SSL certificate vCenter VMware

    I am trying to deploy a new Horizon view 7 based on vSphere environment 6 U2 to replace our pod 5.3 view existing. I have a Windows Server vCenter Server with separate PSC of Windows. I used the PSC signed the SSL certificate for vCenter and downloaded and added the certificate authority root for the required workstations and servers via Group Policy. If I navigate to vCenter from your desktop with CA root installed all is well on the HTTPS front. I added this vCenter Server in my environment view but it appears in red on the dashboard view. I clicked on the vcenter Server and checked the certificate, but at no time should you go green. The two connection servers have the CA root installed and if I launch a browser from the connection to the server itself, then navigate to the vCenter FQDN certificate is approved.

    Any ideas?

    I cannot create pools for this reason that the view is not currently communicate with vCenter as well and it won't let me choose a virtual machine model.

    If you need to know more details please let me know and I'll happily supply.

    Thanks in advance.

    Having re-read the Horizon view documentation 7 to confirm that I had taken the correct steps already, I decided to restart both of my new server connection, that solved the problem. My vCenter server now shows in green in the dashboard and I was able to successful deployment of desktop computers.

  • VMWare v6.0 to 6U1 or 6U2 Upgrade - external PSC - 1603 errors in vCenter Server

    Hi all

    I was wondering if someone met the upgrade a version 6.0 VMWare install to U1 or U2 upgrade and received a 1603 error.

    The installation runs correctly on the external PSC, but when running against the vCenter Server fails and has a 1603 error and did a restore.

    The VCSServiceManager component installation failed with error code "1603". Check the logs for more details

    I tried all the other threads suggesting to have .net installed 3.5, the ipv4 stack and database permissions but are all there.

    Any help would be greatly appreciated.

    For those who have encountered this problem in the future, was the way I solved this:

    Question has been connected to the VMWare SysLog Collector Service. There is a problem with the new syslogcollection MSI being able to upgrade, uninstall or reinstall on the legacy.

    Best way to solve this problem is to remove the reference to the old service of library of Windows Setup syslog collector. The way I did it was to use the Windows Installer CleanUp legacy.

    Post this, remove installation held as scheduled and transmitted "installation VCSServiceManager.

    If you come across this issue - you can test it by trying to run the msi syslogcollector contained in the directory of files binary vCenter.

  • Update/migration - vCenter Server 5.0 on windows-> vCenter Server Applicance 6.0.0 U2?

    Hello, I'm trying to upgrade vSphere for a customer of 5.0 to 6.0.0 U2. I don't foresee any problems with the upgrade of the host, but I'm having a terrible time to vCenter Server upgraded. SSL problems, inventory Service won't start/db issues, etc. This is a very simple configuration with only two hosts, a DS3524 for the shared storage and a vCenter server running on a windows virtual machine. I am simply considering implementation installation vCenter's existing disposal and replacement with a new device. What, exactly, would I lose, do this? vMotion, HA and DRS is put to the top, but nothing fancy or automated.

    Thanks in advance.

    -arthur

    Because your environment is small, I think that a better option is really build a new vCenter from scratch and then guests are leaving the former vCenter to the new... of course, you will lose all historical data (statistics, task, events) of the old host and you will need to re - create clusters on the new vCenter configurations.

    Here is a KB showing how to move an ESXi to one vCenter to another: VMware KB: move a managed ESX ESXi host to a vCenter Server to a different Server vCenter

  • VCenter Server first to 5.5.0U3b update and later update of VMware ESXi ESX / will I have problems?

    Hello

    have trouble when I first updated my signature single vCenter Server and later update my vSphere hosts?

    A vCenter Server Version 5.5.0U3b should be able to manage vSphere Host Version 5.5.0 GA, right?

    Kind regards

    Roland

    The vCenter Server 5.5 update 3 b can manage VMware ESXi ESX release GA to 5.5 5.5 update 3 b, take a look: VMware product interoperability Matrices

    BUT, according to the interoperability matrices and vCenter Server 5.5 update 3 release notes, VMware strongly recommends you upgrade your hosts to 5.5 update 3 b, see:

    What's new

    • Update Support for the SSLv3 Protocol is disabled by default
      Note: In your vSphere environment, you must update vCenter Server vCenter Server 5.5 update 3 b before the update to 5.5 ESXi ESXi update 3 b. vCenter Server will not be able to manage 3B ESXi 5.5 update, if you update ESXi before update vCenter Server to version 5.5 update 3 b. For more information about the sequence in which vSphere environments must be updated, see KB 2057795.
    • VMware strongly recommends you update ESXi hosts to ESXi 5.5 update 3 b management of vCenter Server 5.5 updated 3B.
    VMware does not recommend the reactivation of SSLv3 because of the vulnerability of POODLE. If all you must enable SSLv3, you must activate the SSLv3 Protocol for all components. For more information, see

    KO 2139396

    .
    • Resolved issues. This version of vCenter Server 5.5 update 3 b solves the problems that have been documented in the resolved issues section.
  • SSL certificate for the Security Server external facing

    Dear all,

    Today, I bought an external SSL certificate of DigitCert for our security server. I imported the certificates in the personal certificate (computer account) on the Security Server store. DigiCert provided three certificates, root CA, CA server and the other with the name of our domain. I renamed the vdm to the friendly name of the existing self-signed certificate and used the friendly name for the certificate vdm has our domain name. Subsequently, I rebooted consulting on the Security server. They are all released on except the "Display Blast Secure Gateway" service which entered the suspended state.

    On our facility, we have a connection to the server and a security server. To the Security Server, we use a different domain name for connecting to the server. We have an internal PKI and the connection to the server uses an SSL certificate.

    connection to the server = server01.internaldomain.com

    Security Server = server02.externaldomain.com

    Why the certificate cannot be loaded to view Blast Secure Gateway? I missed something?

    Thank you

    Edy

    I solved it. It was with the private key of the certificate. This is the reason that the Blast Secure Gateway could not load.

  • problem with vCenter Server 4.0 Update 1

    I have ower vCenter Server 4.0 Update 1 upgrade in December, somehow the version number is not right.

    The build number of the show is always 208111 if I trie to reinstall the update 1 only, I can completely uninstall the vCenter Server.

    So, the update seems to be installed anyway nor 100% corectly.

    The vCenter Server Loggenerator also shows me the 208111 build.

    Because of this I also can't update the last Patch1 for Update Manager.

    Way to go VMware... I love how just release notes say "run Setup". Of course, it was all buried a few deep records, not at the root of the zip file.

  • vCenter Server Appliance "URL of repository" evil

    Hey guys,.

    new to this entire VMware environment.

    I am trying install Win Server 2012 and in order to get installed it, I understand that I have to update my current version to 5.0.0 VMware - 455964 I have for later. I was hoping that it would accomplish this by accessing the VMware vCenter Server Appliance in the section "Update." But when I hit 'check updates' I get a:

    Impossible to check updates (error update server being contacted. Please check the network configuration. Couldn't resolve host ' VAPP - updates.vmware.com' URL: http://vapp-updates.vmware.com/vai-catalog/valm/vmw/8e70f769-fd50-4a7a-bee2-2c0d945e23b0/5.0.0.3324.latest/manifest/manifest-latest.xml) on Friday, June 20, 2014 3:02:21 PM GMT - 04:00


    Error...


    So I try to figure out how to invite to get the URL and (current) right to check with success to FIND an update. And if all goes well install it...


    What may be a DNS issue? If so, I have not found a place for the DNS entry. Must be outside of the server appliance?


    Can you help me? Let me know what else I might need to provide to you guys to get somewhere with my question


    Thank you


    lookush

    To configure DNS on the vCSA change the Type of address to SLAAC-IPv6 first and you can add DNS server address and the host name.

    Check this blog for more information: How to configure the vSphere 5 vCenter Server Appliance

  • No VRM server registered with vCenter Server for the site 'Live '.

    I have SRM 6.1 and vSphere replication 6.1 installed on both sites.

    The ECP is connected to the vCenter server.

    I get this error message: failed to create the protection group. No VRM server registered with vCenter Server for the site 'Live '.

    Screenshot attached, no one knows what is happening here?

    Capture.jpg

    However, there was a mismatch in the meantime server on all except VRA in the remote site, it is now resolved and the issue disappeared.

    Strange, how the error related to the site online, however.

    Thank you for pointing me in the right direction.

Maybe you are looking for

  • Resolution screen NB200 - 10G problem

    Hello My new NB200 does not display the toolbar when it is started. This is where, I think, because if I click madly under the visible screen sometimes there is a reaction. This seems to be a problem of screen resolution. When the system starts, wind

  • Cannot install Windows XP on Equium A200

    Hello I uninstalled vista on my laptop Equium A200. My idea was (a popular) to uninstall vista and XP, get rid of the unstable operating system (sorry, personal opinion) Of course the XP installation noted that I have no disks on my pc. I got the SAT

  • How to test the stability of the communication and to calculate ber using the CVI?

    Our Chief Engineer gave me a task yesterday. He asked me to make testing of software and to calculate the error rate binary we would like to know our stability of communication. However, I never touched this aspect of knowledge. I know a bit about th

  • Router Netgear WNA3100 give up wireless connection with various devices.

    original title: netgear abandons the connection I have a netgear WNA3100 wireless adapter, our router is a WII-G300N buffalo: router wireless Nfiniti broadband the laptop that I use has no connection problem and stay connected so I know that's not th

  • The song in WMP11 file type conversion

    How you, or you can convert the file type of a song in windows Media Player 11 Windows XP 32-bit SP3 Fully updated Running, Avast, MBAM, SAS Never a Noton, trend, or McAfee. Nothing is wrong, and the information above is not relevant to the issue. Yo