VxRail: Unable to Import vCenter Root Certificates Due to Empty or Corrupted CRL Files

요약: Unable to import vCenter root certificates due to empty or corrupted CRL file.

이 문서는 다음에 적용됩니다. 이 문서는 다음에 적용되지 않습니다. 이 문서는 특정 제품과 관련이 없습니다. 모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.

증상

When following Dell KB article VxRail: How to manually import vCenter SSL certificate on VxRail Manager to manually import vCenter server certificate, errors display when converting the .r files:

#openssl crl -outform der -in /tmp/certificates/certs/lin/e1f7261b.r1 -out newcrltfile1
unable to load CRL

OR

#cert_util_init.py script failed with error:
Failed to find a matching root CA Certificate/CRL set that could verify vCenter certificate
OR
Failed to installed vCenter certificate with Chrome, error:
The Private Key for this Client Certificate is missing or invalid OR Invalid or corrupt file

원인

The vCenter root Certificate CRL file is empty or corrupted.

How to check if this is the issue:

  1. Download and extract the latest vCenter root certificate (Download and install vCenter Server root certificates to avoid web browser certificate warningsThis hyperlink is taking you to a website outside of Dell Technologies.).
  2. Check if any CRL file is empty or corrupted (screenshot below):
    crl error

Or

  1. SSH to PSC and vCenter with root credential
  2. Change to the directory /etc/ssl/certs.
  3. Check if any .r file is 0 bytes or corrupted.

해결

To resolve this issue:

  1. If any empty or corrupted CRL file is found on the PSC and or vCenter, take OFFLINE snapshots for PSC and vCenter before proceeding.
  2. Follow instructions from VMware KB article 59555 to run fix_crl.sh script (vmware-vapi-endpoint fails to start or crashes after upgrading to vCenter Server 6.5 Update 2This hyperlink is taking you to a website outside of Dell Technologies.). The script should be performed on both VCSA and PSC.
  3. On vCenter, go to folder /etc/vmware-vpx/docRoot/certs.
  4. If the empty (0 bytes) or corrupted CRL files still exist, DELETE the file from this directory.
  5. Reboot PSC and vCenter after fix_crl.sh.
  6. Reimport the vCenter root certificate to the VxRail manager.

해당 제품

VxRail, VxRail Software
문서 속성
문서 번호: 000194669
문서 유형: Solution
마지막 수정 시간: 14 8월 2025
버전:  11
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.