Siirry pääsisältöön
  • Tee tilauksia nopeasti ja helposti
  • Tarkastele tilauksia ja seuraa lähetyksen tilaa
  • Luo tuoteluettelo ja käytä sitä
  • Hallitse Dell EMC-sivustoja, tuotteita ja tuote-tason yhteystietoja yrityksen hallinnan avulla.

OpenManage Integration for VMware vCenter Version 4.0 Web Client User's Guide

How do I resolve error code 2000000 caused by VMware Certificate Authority (VMCA)?

When you run the vSphere certificate manager and replace the vCenter server or Platform Controller Service (PSC) certificate with a new CA certificate and key for vCenter 6.0, OMIVV displays error code 2000000 and throws an exception.

Updating the ssl Anchors in Windows vSphere 6.0

Resolution: To resolve the exception, you should update the ssl Anchors for the services. The ssl Anchors can be updated by running the ls_update_certs.py scripts on PSC. The script takes the old certificate thumbprint as the input argument and the new certificate is installed. The old certificate is the certificate before the replacement and the new certificate is the certificate after the replacement. Visit http://kb.vmware.com/selfservice/search.do?cmd=displayKC&docType=kc&docTypeID=DT_KB_1_1&externalId=2121701 and http://kb.vmware.com/selfservice/search.do?cmd=displayKC&docType=kc&docTypeID=DT_KB_1_1&externalId=2121689 for more information.

  1. Download the lstoolutil.py.zip file from http://kb.vmware.com/selfservice/search.do?cmd=displayKC&docType=kc&docTypeID=DT_KB_1_1&externalId=2121701.
  2. Copy the lstoolutil.py file to the %VMWARE_CIS_HOME%"\VMware Identity Services\lstool\scripts\ folder.
    NOTE: Do not replace the lstoolutil.py file if you are using vSphere 6.0 Update 1.

You can use the following relevant procedures to update the ssl Anchors:

The output obtained from the mentioned procedures should display Updated 24 service (s) and Updated 26 service (s) respectively. If the output displayed is Updated 0 service (s), the old certificate thumbprint is incorrect. You can perform the following steps to retrieve the old certificate thumbprint. Also, use the following procedure to retrieve the old certificate thumbprint, if vCenter Certificate Manager is not used to replace the certificates:
NOTE: Run the ls_update_certs.py with the old thumbprint obtained.
  1. Retrieve the old certificate from the Managed Object Browser (MOB). See Retrieving the old certificate from Managed Object Browser (MOB).
  2. Extract the thumbprint from the old certificate. See Extracting thumbprint from the old certificate.

Version Affected: 3.0 and later, vCenter 6.0 and later


Arvostele tämä sisältö

Tarkka
Hyödyllinen
Helppo hahmottaa
Oliko tästä artikkelista hyötyä?
0/3000 characters
  Anna arvioinnit (1–5 tähteä).
  Anna arvioinnit (1–5 tähteä).
  Anna arvioinnit (1–5 tähteä).
  Valitse, oliko artikkelista mielestäsi hyötyä vai ei.
  Kommenteissa ei voi olla seuraavia erikoismerkkejä: <>()\