VxRail: Unable to apply vCenter Custom Certificate
Summary: Certificate manager shows “Unable to validate the chain of trust” and “INVALID_KEY” when a vCenter SSL certificate is installed, because the bundle misses an intermediate cert, breaking trust chain. ...
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
Received a new SSL certificate from the customer CA, the customer is unable to replace the MACHINE SSL in the VC certificate manager.
From the CLI, Certificate Manager errors appear with this response:
Error: certificate-manager: Unable to validate the chain of trust for the provided SSL certificate and Root. C = US, ST = MA, L = Boston, ................ ...................... 20 at 0 depth lookup: unable to get local issuer certificate

Figure 1. Certificate Manager Errors
From the Certificate-manager.log:
2024-06-24T01:12:33.327Z INFO certificate-manager Command executed successfully 2024-06-24T01:12:33.327Z INFO certificate-manager Certificate backup created successfully 2024-06-24T01:12:33.536Z ERROR certificate-manager ERROR:: INVALID_KEY, the private key doesnot match the certificate. Please provide a valid certificate and Key pair. 2024-06-24T01:12:33.536Z ERROR certificate-manager Error while replacing Machine SSL Cert, please see /var/log/vmware/vmcad/certificate-manager.log for more information. 2024-06-24T01:12:33.536Z ERROR certificate-manager ERROR:: INVALID_KEY, the private key doesnot match the certificate. Please provide a valid certificate and Key pair. 2024-06-24T01:12:33.536Z INFO certificate-manager Performing rollback of Machine SSL Cert... 2024-06-24T01:12:33.536Z INFO certificate-manager Running command :- ['/usr/lib/vmware-vmafd/bin/vecs-cli', 'entry', 'getkey', '--store', 'BACKUP_STORE', '--alias', 'bkp___MACHINE_CERT', '--output', '/storage/certmanager/rollback/MACHINE_SSL_CERT_bkp.priv'] 2024-06-24T01:12:33.542Z INFO certificate-manager Command output :-
Cause
The error above indicates an incomplete trust chain.
The customer was missing a second intermediate certificate.
The customer was missing a second intermediate certificate.
Resolution
To resolve this issue, combine the two intermediate certificates together.
For more information, review the documentation about replacing with customer certificates:
https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-authentication/GUID-FEEAB88E-D888-403F-AA62-1074585F7FEB.html
Affected Products
VxRail, VxRail Appliance Family, VxRail Appliance SeriesArticle Properties
Article Number: 000226729
Article Type: Solution
Last Modified: 05 ربيع الأول 1448
Version: 3
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.