连接vSphere 时发现无法验证,报 500、400 错误,进入 5480 端口的 VAM 发现状态正常,但是证书服务出错,同时查看网页证书发现已过期两天。基本确定是证书问题。检索后参考以下文章进行修复,附件如下。
VMware vCenter证书过期解决方法 - Sawyerhan - 博客园
使用压缩包中的 checksts.py 脚本进行检查,发现 sts 证书未过期。
shellroot@ZJvCSA1 [ ~ ]# ls checksts.py root@ZJvCSA1 [ ~ ]# python checksts.py 2 VALID CERTS ================ LEAF CERTS: [] Certificate 51:6E:59:84:E7:2D:BD:64:25:28:1F:61:5A:66:28:A3:D1:F6:A1:71 will expire in 2913 days (8 years). ROOT CERTS: [] Certificate E7:D0:E7:94:7C:A4:14:42:B9:81:B5:CE:2A:81:E4:30:66:3E:FD:A7 will expire in 2913 days (8 years). 0 EXPIRED CERTS ================ LEAF CERTS: None ROOT CERTS: None
使用如下命令检查后发现
MACHINE_SSL_CERT、machine、vsphere-webclient、vpxd、vpxd-extension、data-encipherment
均已过期
shellroot@ZJvCSA1 [ ~ ]# for store in $(/usr/lib/vmware-vmafd/bin/vecs-cli store list | grep -v TRUSTED_ROOT_CRLS); do echo "[*] Store :" $store; /usr/lib/vmware-vmafd/bin/vecs-cli entry list --store $store --text | grep -ie "Alias" -ie "Not After";done; [*] Store : MACHINE_SSL_CERT Alias : __MACHINE_CERT Not After : Oct 20 23:19:10 2025 GMT [*] Store : TRUSTED_ROOTS Alias : e7d0e7947ca41442b981b5ce2a81e430663efda7 Not After : Oct 15 11:19:09 2032 GMT [*] Store : machine Alias : machine Not After : Oct 20 11:10:23 2025 GMT [*] Store : vsphere-webclient Alias : vsphere-webclient Not After : Oct 20 11:10:25 2025 GMT [*] Store : vpxd Alias : vpxd Not After : Oct 20 11:10:27 2025 GMT [*] Store : vpxd-extension Alias : vpxd-extension Not After : Oct 20 11:10:29 2025 GMT [*] Store : APPLMGMT_PASSWORD [*] Store : data-encipherment Alias : data-encipherment Not After : Oct 20 11:13:25 2025 GMT [*] Store : SMS Alias : sms_self_signed Not After : Oct 21 11:27:10 2032 GMT
运行 certificate-manager 进行修复,需要验证 admin 账号以及输入正确FQDN(56、57 行)一路确认即可
自动重启完成后问题解决
shellroot@ZJvCSA1 [ ~ ]# /usr/lib/vmware-vmca/bin/certificate-manager _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ | | | *** Welcome to the vSphere 6.7 Certificate Manager *** | | | | -- Select Operation -- | | | | 1. Replace Machine SSL certificate with Custom Certificate | | | | 2. Replace VMCA Root certificate with Custom Signing | | Certificate and replace all Certificates | | | | 3. Replace Machine SSL certificate with VMCA Certificate | | | | 4. Regenerate a new VMCA Root Certificate and | | replace all certificates | | | | 5. Replace Solution user certificates with | | Custom Certificate | | | | 6. Replace Solution user certificates with VMCA certificates | | | | 7. Revert last performed operation by re-publishing old | | certificates | | | | 8. Reset all Certificates | |_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _| Note : Use Ctrl-D to exit. Option[1 to 8]: 8 Do you wish to generate all certificates using configuration file : Option[Y/N] ? : y Please provide valid SSO and VC privileged user credential to perform certificate operations. Enter username [Administrator@vsphere.local]:Administrator@xmysd.local Enter password: Please configure certool.cfg with proper values before proceeding to next step. Press Enter key to skip optional parameters or use Default value. Enter proper value for 'Country' [Default value : US] : CN Enter proper value for 'Name' [Default value : CA] : Enter proper value for 'Organization' [Default value : VMware] : xmysd Enter proper value for 'OrgUnit' [Default value : VMware Engineering] : Enter proper value for 'State' [Default value : California] : Enter proper value for 'Locality' [Default value : Palo Alto] : Enter proper value for 'IPAddress' (Provide comma separated values for multiple IP addresses) [optional] : Enter proper value for 'Email' [Default value : email@acme.com] : Enter proper value for 'Hostname' (Provide comma separated values for multiple Hostname entries) [Enter valid Fully Qualified Domain Name(FQDN), For Example : example.domain.com] : zjvcsa1.xmysd.com Enter proper value for VMCA 'Name' :zjvcsa1.xmysd.com Continue operation : Option[Y/N] ? : y You are going to reset by regenerating Root Certificate and replace all certificates using VMCA Continue operation : Option[Y/N] ? : y Get site nameCompleted [Reset Machine SSL Cert...] default-site Lookup all services Get service default-site:fdf5a246-a369-428b-ba32-aab40d30a983 Update service default-site:fdf5a246-a369-428b-ba32-aab40d30a983; spec: /tmp/svcspec_9_z_09zo Get service default-site:90730e62-c237-491c-94a3-691b6bc5fb3f Update service default-site:90730e62-c237-491c-94a3-691b6bc5fb3f; spec: /tmp/svcspec_b8hlqrjl Get service default-site:93c99a35-6819-4a22-8f12-bac8c791fe0b Update service default-site:93c99a35-6819-4a22-8f12-bac8c791fe0b; spec: /tmp/svcspec_v0h21niv Get service f9b7ab57-d31a-472b-baca-a8fc73dffa5e Update service f9b7ab57-d31a-472b-baca-a8fc73dffa5e; spec: /tmp/svcspec_620rd825 Get service 47756137-6b86-4a5a-9f69-ffd9a765efa5 Update service 47756137-6b86-4a5a-9f69-ffd9a765efa5; spec: /tmp/svcspec_6768s48i Get service 4a401699-4198-4e2b-b38c-0d1210dbbd41 Update service 4a401699-4198-4e2b-b38c-0d1210dbbd41; spec: /tmp/svcspec_231ve0br Get service f4558b2b-1935-4d12-9ce9-b546f75e619f Update service f4558b2b-1935-4d12-9ce9-b546f75e619f; spec: /tmp/svcspec_n8w1ki48 Get service e015ce62-1ee6-487d-9893-f7cc7fb7d7c5 Update service e015ce62-1ee6-487d-9893-f7cc7fb7d7c5; spec: /tmp/svcspec_06i6ocfs Get service 1db62bf3-7189-44c5-8249-5812e39b9466 Update service 1db62bf3-7189-44c5-8249-5812e39b9466; spec: /tmp/svcspec_t2ci1rvv Get service f1a976cb-7010-4053-866b-f1f4690d0afd_kv Update service f1a976cb-7010-4053-866b-f1f4690d0afd_kv; spec: /tmp/svcspec_1cg7rxq9 Get service 119e4f2c-470b-4f0e-9d3f-f7c63f6bba36 Update service 119e4f2c-470b-4f0e-9d3f-f7c63f6bba36; spec: /tmp/svcspec_w2u1hnf8 Get service 605f5a7d-4273-4c3b-8cc6-ae1eaa0fd0c2 Update service 605f5a7d-4273-4c3b-8cc6-ae1eaa0fd0c2; spec: /tmp/svcspec_u64kl0zi Get service f1a976cb-7010-4053-866b-f1f4690d0afd_authz Update service f1a976cb-7010-4053-866b-f1f4690d0afd_authz; spec: /tmp/svcspec_r2xbpwg3 Get service c400991e-062a-4788-baf9-c709633865e7 Update service c400991e-062a-4788-baf9-c709633865e7; spec: /tmp/svcspec_bxqbi7zb Get service f1a976cb-7010-4053-866b-f1f4690d0afd Update service f1a976cb-7010-4053-866b-f1f4690d0afd; spec: /tmp/svcspec_ilwddh4a Get service 6da2c3a6-d9e8-4ac1-9065-78f65faa3127 Update service 6da2c3a6-d9e8-4ac1-9065-78f65faa3127; spec: /tmp/svcspec_uaxi4a2g Get service ba86c811-0157-4237-86b1-099aa1989e68 Update service ba86c811-0157-4237-86b1-099aa1989e68; spec: /tmp/svcspec_up81wd9c Get service 86fb758e-1d65-47e8-a2ad-f6da2b48421d Update service 86fb758e-1d65-47e8-a2ad-f6da2b48421d; spec: /tmp/svcspec_53adi_lc Get service 699f0502-d4f9-485b-a8c9-8f969438d68c Update service 699f0502-d4f9-485b-a8c9-8f969438d68c; spec: /tmp/svcspec_cbwmzggu Get service 9a9ab827-cbdc-4b57-bf53-6296d3ba5c48 Update service 9a9ab827-cbdc-4b57-bf53-6296d3ba5c48; spec: /tmp/svcspec_sxl8f42c Get service 046962bc-32b2-4bde-9a68-284374a2a9fc Update service 046962bc-32b2-4bde-9a68-284374a2a9fc; spec: /tmp/svcspec_k333m5p8 Get service 56f64b2c-c9cc-4e75-abcd-8d76448e72f7 Update service 56f64b2c-c9cc-4e75-abcd-8d76448e72f7; spec: /tmp/svcspec_j1n5lwk2 Get service d71471a0-7314-4d33-b76e-306372940629 Update service d71471a0-7314-4d33-b76e-306372940629; spec: /tmp/svcspec_bnq4vxsn Get service 50d63d29-4fb7-48b8-87b4-56c5f064bbc8 Update service 50d63d29-4fb7-48b8-87b4-56c5f064bbc8; spec: /tmp/svcspec__ucdp1f4 Get service 108fa898-771e-49e3-b8bf-900a4ad023ad Update service 108fa898-771e-49e3-b8bf-900a4ad023ad; spec: /tmp/svcspec_nkg05vjo Get service ecbbe7b2-7e63-48e4-b9fb-89267f47093e Update service ecbbe7b2-7e63-48e4-b9fb-89267f47093e; spec: /tmp/svcspec_zxvq_arc Get service e196c98d-d90d-4c43-a96f-521ffb0627ba Update service e196c98d-d90d-4c43-a96f-521ffb0627ba; spec: /tmp/svcspec_k5a1hy2f Get service e95abbb3-6ad7-4f26-a7bd-7316e08d33e1 Update service e95abbb3-6ad7-4f26-a7bd-7316e08d33e1; spec: /tmp/svcspec_271ikewg Get service 2f541a5c-bb1c-45b4-941d-fd4fefa5d095 Update service 2f541a5c-bb1c-45b4-941d-fd4fefa5d095; spec: /tmp/svcspec_dq2arwb4 Get service b221b437-f1f0-40da-9972-3fe1024b7fa4 Update service b221b437-f1f0-40da-9972-3fe1024b7fa4; spec: /tmp/svcspec_iwxmf5e4 Get service 27b3665c-8ea5-427a-9063-5043632e27cc Update service 27b3665c-8ea5-427a-9063-5043632e27cc; spec: /tmp/svcspec_i25mnnoe Get service f12c320a-a2a9-492c-8178-f1b5dc48fe56 Update service f12c320a-a2a9-492c-8178-f1b5dc48fe56; spec: /tmp/svcspec_ews3dbn6 Get service 0336210c-e126-493e-849e-501282c0252a Update service 0336210c-e126-493e-849e-501282c0252a; spec: /tmp/svcspec_zo0p7fr1 Get service d71471a0-7314-4d33-b76e-306372940629_com.vmware.vsphere.client Don't update service d71471a0-7314-4d33-b76e-306372940629_com.vmware.vsphere.client Get service 75326926-d261-426d-a81c-e59b501eaba0 Update service 75326926-d261-426d-a81c-e59b501eaba0; spec: /tmp/svcspec_ilkow9mi Get service d71471a0-7314-4d33-b76e-306372940629_com.apcc.pcns.PowerChutePlugin.PCNS1 Don't update service d71471a0-7314-4d33-b76e-306372940629_com.apcc.pcns.PowerChutePlugin.PCNS1 Updated 34 service(s) Status : 60% Completed [Reset vpxd-extension Cert...] 2024-10-24T02:08:02.204Z Updating certificate for "com.vmware.vim.eam" extension 2024-10-24T02:08:03.424Z Updating certificate for "com.vmware.rbd" extension 2024-10-24T02:08:04.567Z Updating certificate for "com.vmware.imagebuilder" extension Reset status : 100% Completed [Reset completed successfully]