Passer au contenu principal
  • Passer des commandes rapidement et facilement
  • Afficher les commandes et suivre l’état de votre expédition
  • Créez et accédez à une liste de vos produits
  • Gérer vos sites, vos produits et vos contacts au niveau des produits Dell EMC à l’aide de la rubrique Gestion des informations de l’entreprise.

OpenManage Integration for VMware vCenter Version 4.0 Web Client User's Guide

How do I resolve error code 2000000 caused by VMware Certificate Authority (VMCA)?

When you run the vSphere certificate manager and replace the vCenter server or Platform Controller Service (PSC) certificate with a new CA certificate and key for vCenter 6.0, OMIVV displays error code 2000000 and throws an exception.

Updating the ssl Anchors in Windows vSphere 6.0

Resolution: To resolve the exception, you should update the ssl Anchors for the services. The ssl Anchors can be updated by running the ls_update_certs.py scripts on PSC. The script takes the old certificate thumbprint as the input argument and the new certificate is installed. The old certificate is the certificate before the replacement and the new certificate is the certificate after the replacement. Visit http://kb.vmware.com/selfservice/search.do?cmd=displayKC&docType=kc&docTypeID=DT_KB_1_1&externalId=2121701 and http://kb.vmware.com/selfservice/search.do?cmd=displayKC&docType=kc&docTypeID=DT_KB_1_1&externalId=2121689 for more information.

  1. Download the lstoolutil.py.zip file from http://kb.vmware.com/selfservice/search.do?cmd=displayKC&docType=kc&docTypeID=DT_KB_1_1&externalId=2121701.
  2. Copy the lstoolutil.py file to the %VMWARE_CIS_HOME%"\VMware Identity Services\lstool\scripts\ folder.
    NOTE: Do not replace the lstoolutil.py file if you are using vSphere 6.0 Update 1.

You can use the following relevant procedures to update the ssl Anchors:

The output obtained from the mentioned procedures should display Updated 24 service (s) and Updated 26 service (s) respectively. If the output displayed is Updated 0 service (s), the old certificate thumbprint is incorrect. You can perform the following steps to retrieve the old certificate thumbprint. Also, use the following procedure to retrieve the old certificate thumbprint, if vCenter Certificate Manager is not used to replace the certificates:
NOTE: Run the ls_update_certs.py with the old thumbprint obtained.
  1. Retrieve the old certificate from the Managed Object Browser (MOB). See Retrieving the old certificate from Managed Object Browser (MOB).
  2. Extract the thumbprint from the old certificate. See Extracting thumbprint from the old certificate.

Version Affected: 3.0 and later, vCenter 6.0 and later


Évaluez ce contenu

Précis
Utile
Facile à comprendre
Avez-vous trouvé cet article utile ?
0/3000 characters
  Veuillez attribuer une note (1 à 5 étoiles).
  Veuillez attribuer une note (1 à 5 étoiles).
  Veuillez attribuer une note (1 à 5 étoiles).
  Veuillez indiquer si l’article a été utile ou non.
  Les commentaires ne doivent pas contenir les caractères spéciaux : <>()\