Posts tagged ‘vcsa’
How to renew vSphere 6.5 & 6.7 certificates.
When the VCenter Certificate is expired , you will be blocked from logging in to the VCenter . However , the Appliance Management will continue to work. Be noted that there a 2 categories of certificates.
- VMware Security Token Service (STS)
- Solution , Machine , Root and Other certificates.
Import Notes:
- You could avoid all these messy steps , had you monitor and check for the
warnings on the VCenter Administration page for Certificate expiry events. - For Windows based VCenter , you can refer the same KB’s mentioned here for the detailed steps.
- You may face an error when uploading the scripts to the VCSA via WinSCP . The Solution is provided in the same KB’s.
- Certificate Manager may fail during the process , you could refer the https://mueller-tech.com/2019/06/28/replacing-expired-certificates/ for the solution.
I used the below mentioned steps to confirm the expiry date for both of these certificates
STS – Please refer the KB:
https://kb.vmware.com/s/article/79248 (It will require to download a script – checksts.py)
Others – Run the below command in the VCSA.
for i in $(/usr/lib/vmware-vmafd/bin/vecs-cli store list); do echo STORE $i; sudo /usr/lib/vmware-vmafd/bin/vecs-cli entry list –store $i –text | egrep “Alias|Not After”; done
In my situation , both of the certificate types were expired and I had to replace all of them. To replace the STS certifcate , you could utilize a script provided by VMWare (fixsts.sh) using the KB : https://kb.vmware.com/s/article/76719
Once it is done , you need to restart the VCenter services using the below commands.
service-control –stop –all
service-control –start –all
service-control –status.
Thereafter , you could proceed to replace the other certificates using the VSphere Certificate Manager https://kb.vmware.com/s/article/2112283
VCSA6.7 and Veeam B&R Issues
Recently we were upgrading our ESXi Infrastructure from ESXi 6.0 to 6.7.During this process we kicked off the migration process with our VCenter Server 6.0 with the intention to move it to a VCSA 6.7 . Everything went well . But on the following day we started receiving Backup job failure alerts from Veeam Server.
After few google searches we came to know that the Veeam B&R need to be upgraded with U3 to be fully be compatible with Photon based VCSA 6.7 .
Good Luck with your VSphere Upgrades.