VxRail: Unable to Import vCenter Root Certificates Due to Empty or Corrupted CRL Files
Summary: Unable to import vCenter root certificates due to empty or corrupted CRL file.
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Symptoms
When following Dell KB article VxRail: How to manually import vCenter SSL certificate on VxRail Manager to manually import vCenter server certificate, errors display when converting the .r files:
#openssl crl -outform der -in /tmp/certificates/certs/lin/e1f7261b.r1 -out newcrltfile1 unable to load CRL
OR
#cert_util_init.py script failed with error: Failed to find a matching root CA Certificate/CRL set that could verify vCenter certificate OR Failed to installed vCenter certificate with Chrome, error: The Private Key for this Client Certificate is missing or invalid OR Invalid or corrupt file
Cause
The vCenter root Certificate CRL file is empty or corrupted.
How to check if this is the issue:
- Download and extract the latest vCenter root certificate (Download and install vCenter Server root certificates to avoid web browser certificate warnings
).
- Check if any CRL file is empty or corrupted (screenshot below):

Or
- SSH to PSC and vCenter with root credential
- Change to the directory
/etc/ssl/certs. - Check if any
.rfile is 0 bytes or corrupted.
Resolution
To resolve this issue:
- If any empty or corrupted CRL file is found on the PSC and or vCenter, take OFFLINE snapshots for PSC and vCenter before proceeding.
- Follow instructions from VMware KB article 59555 to run fix_crl.sh script (
vmware-vapi-endpointfails to start or crashes after upgrading to vCenter Server 6.5 Update 2). The script should be performed on both VCSA and PSC.
- On vCenter, go to folder
/etc/vmware-vpx/docRoot/certs. - If the empty (0 bytes) or corrupted CRL files still exist, DELETE the file from this directory.
- Reboot PSC and vCenter after
fix_crl.sh. - Reimport the vCenter root certificate to the VxRail manager.
Affected Products
VxRail, VxRail SoftwareArticle Properties
Article Number: 000194669
Article Type: Solution
Last Modified: 14 Aug 2025
Version: 11
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.