Dell VxRail: How to Manually Import vCenter SSL Certificate on VxRail Manager
요약: Step-by-step instructions to manually import the vCenter SSL certificate on VxRail.
이 문서는 다음에 적용됩니다.
이 문서는 다음에 적용되지 않습니다.
이 문서는 특정 제품과 관련이 없습니다.
모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.
증상
In some situations, it is necessary to manually import the SSL certificates in vCenter after VxRail initial deployment.
원인
Replacing vCenter SSL self-signed certificate with a previously owned certificate.
해결
A Python script is attached to this article in a .zip file (check the bottom of the article) to provide the importing process. Run this script AS ROOT on VxRail Manager, and use --help to obtain usage. Remove the script after use.
Note: The script works on VxRail 4.5.x, 4.7.x, 7.x, and 8.x. Script in this article was updated on May 23, 2025. Starting from 7.0.480, the script has been added into VxRail Manager at
/mystic/ssl/cert_util.py. You can run this script directly.
Follow these steps to replace certificates on VxRail Manager:
- Download the python script cert_util_pkb.zip and upload it to VxRail Manager.
- You must now use SSH log in to VxRail Manager and switch to ROOT user.
- Extract script cert_util_pkb.zip:
# unzip cert_util_pkb.zip
- Run the script:
# python cert_util.py
- Wait for the VxRail plug-in UI to load. It may take up to 10 minutes for the UI to be read.
Example script output:
vxm:/home/mystic # python cert_util.py Verify certificate against vCenter vcluster101-vcsa.vv003.local Downloaded root CA certificate zip to /tmp/tmpw2w8j7_r Downloaded root CA certificate zip from vcluster101-vcsa.vv003.local Found certificates ['certs/lin/53f38aa6.0', 'certs/lin/53f38aa6.r0'] that can verify server certificate Clean up existing certificates in /var/lib/vmware-marvin/trust/ - Removing /var/lib/vmware-marvin/trust/lin/53f38aa6.r0 - Removing /var/lib/vmware-marvin/trust/lin/53f38aa6.0 Clean up existing crl files in /var/lib/vmware-marvin/trust/crl/ Root CA certificate /tmp/certs/lin is saved at /var/lib/vmware-marvin/trust/. Remove /tmp/certs directory. Delete saved CRL info in cacheservice... 1 1 Restarting vmware-marvin service... Restarting runjars service...
추가 정보
Sometimes it may be necessary to import all certificates, not only the ones with the higher numbers.
See this published video:
해당 제품
VxRail, VxRail Software첨부 파일
문서 속성
문서 번호: 000077894
문서 유형: Solution
마지막 수정 시간: 23 5월 2025
버전: 57
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.