{"id":7369,"date":"2023-11-28T19:50:36","date_gmt":"2023-11-28T18:50:36","guid":{"rendered":"https:\/\/tomaskalabis.com\/wordpress\/?p=7369"},"modified":"2023-11-28T19:53:19","modified_gmt":"2023-11-28T18:53:19","slug":"upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again","status":"publish","type":"post","link":"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/","title":{"rendered":"Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again."},"content":{"rendered":"\n\n\n<h3>Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again.<\/h3>\n<p class=\"p3\">We just started a upgrade process of VCSA 7.0.3 to the lastest build of VCSA 8.0.2. The customer migrated the VCSA from 5.5 &gt; 6.0 &gt; 6.5 and 7.0. When we were in stage 2 of upgrade, the validation failed on the \u201cRegenerate certificates for sso and try again\u201d<\/p>\n<p><a href=\"https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2023\/11\/Screenshot-2023-11-28-at-14.56.26.png\"><img decoding=\"async\" loading=\"lazy\" class=\"size-large wp-image-7371 aligncenter\" src=\"https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2023\/11\/Screenshot-2023-11-28-at-14.56.26-494x260.png\" alt=\"\" width=\"494\" height=\"260\" srcset=\"https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2023\/11\/Screenshot-2023-11-28-at-14.56.26-494x260.png 494w, https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2023\/11\/Screenshot-2023-11-28-at-14.56.26-288x152.png 288w, https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2023\/11\/Screenshot-2023-11-28-at-14.56.26-768x405.png 768w, https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2023\/11\/Screenshot-2023-11-28-at-14.56.26.png 1248w\" sizes=\"(max-width: 494px) 100vw, 494px\" \/><\/a><\/p>\n<h4 class=\"p3\">Please do a SNAPSHOT or BACKUP of your VCSA, before follow steps below<\/h4>\n<p class=\"p3\">So we connected to the VCSA source appliance and run certification manager (\/usr\/lib\/vmware-vmca\/bin\/certificate-manager). We choose the option 8 -\u201eReset all Certificates\u201c and answer the required information. Wait few minutes, the services in VCSA are restarted.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2023\/06\/Screenshot-2023-06-23-at-12.26.00-494x209.png\" \/><\/p>\n<p class=\"p3\">We thought that if we started the validation in stage 2 again, that the problem would go away, not nothing happens &#8211; we still had the same error with sso certificates.<\/p>\n<p class=\"p3\">When we tried to check the certificate on the vcenter UI, the cert was sucessfully renewed. But when we put the<\/p>\n<p class=\"p3\"><em>https:\/\/&lt;vcenter\/psc fqdn&gt;:7444\/lookupservice\/sdk<\/em> we got a old expired certificate and this was a main issue.<\/p>\n<h4 class=\"p3\">The next steps was\u00a0<\/h4>\n<p class=\"p3\">Regenerate a new VMCA Root Certificate and replace all certificates (option 4 in cert manager)<\/p>\n<ul>\n<li class=\"p3\">Download the attached\u00a0<a href=\"https:\/\/kb.vmware.com\/s\/article\/76719\" target=\"_blank\" rel=\"noopener\">fixsts.sh<\/a>\u00a0script from this article and upload to the impacted PSC or vCenter Server\u00a0with Embedded PSC to\u00a0the\u00a0\/tmp\u00a0folder.<\/li>\n<li class=\"p3\">If the connection to upload to the vCenter by the SCP client is rejected, run this from an SSH session to the vCenter:# chsh -s \/bin\/bash<\/li>\n<li class=\"p3\">Connect to the PSC or vCenter Server with an SSH session if you have not already per Step 2.<\/li>\n<li class=\"p3\">Navigate to the \/tmp directory:# cd \/tmp<\/li>\n<li class=\"p3\">make the file\u00a0executable:# chmod +x fixsts.sh<\/li>\n<li class=\"p3\">Run the script:# .\/fixsts.sh<\/li>\n<li class=\"p3\">Restart services on all vCenters and\/or PSCs in your SSO domain by using below commands:# service-control &#8211;stop &#8211;all &amp;&amp; service-control &#8211;start &#8211;all<\/li>\n<li class=\"p3\">run a \/usr\/lib\/vmware-vmca\/bin\/certificate-manager and choose option 4 &#8211; Regenerate a new VMCA Root Certificate and replace all certificates<\/li>\n<li class=\"p3\">reboot the VCSA appliance<\/li>\n<\/ul>\n<p class=\"p3\"><strong>after restart of VCSA, we checked<span class=\"Apple-converted-space\">\u00a0 <\/span>the https:\/\/&lt;vcenter\/psc fqdn&gt;:7444\/lookupservice\/sdk and cert was still expired.<\/strong><\/p>\n<p class=\"p3\">we still didn&#8217;t understand why the STS certificate was not being renewed, but the answer was the upgrade path from VCSA 5.5.<\/p>\n<p class=\"p3\">Modify the below file:<\/p>\n<ul>\n<li class=\"p3\"><b>\/usr\/lib\/vmware-sso\/vmware-sts\/conf\/server.xml<\/b><\/li>\n<li class=\"p3\">Modify the 2 entries in the server.xml which has &#8222;<b>STS_INTERNAL_SSL_CERT<\/b>&#8220; to &#8222;<b>MACHINE_SSL_CERT<\/b>&#8220; .<\/li>\n<li class=\"p3\">restart services &#8211; service-control &#8211;stop &#8211;all &amp;&amp; service-control &#8211;start &#8211;all<\/li>\n<\/ul>\n<p class=\"p3\">Now are you able to sucessfully continue with stage 2 of upgrade VCSA to 8.0.2.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again. We just started a upgrade process of VCSA 7.0.3 to the lastest build of &#8230;<\/p>\n","protected":false},"author":2,"featured_media":7010,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[225],"tags":[205,276,80],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v22.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again. - tomaskalabis.com<\/title>\n<meta name=\"description\" content=\"Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/\" \/>\n<meta property=\"og:locale\" content=\"cs_CZ\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again. - tomaskalabis.com\" \/>\n<meta property=\"og:description\" content=\"Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/\" \/>\n<meta property=\"og:site_name\" content=\"tomaskalabis.com\" \/>\n<meta property=\"article:published_time\" content=\"2023-11-28T18:50:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-11-28T18:53:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2021\/12\/vmware-vsphere-logo.png\" \/>\n\t<meta property=\"og:image:width\" content=\"166\" \/>\n\t<meta property=\"og:image:height\" content=\"166\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Tomas Kalabis\" \/>\n<meta name=\"twitter:label1\" content=\"Napsal(a)\" \/>\n\t<meta name=\"twitter:data1\" content=\"Tomas Kalabis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Odhadovan\u00e1 doba \u010dten\u00ed\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minuty\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/\",\"url\":\"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/\",\"name\":\"Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again. - tomaskalabis.com\",\"isPartOf\":{\"@id\":\"https:\/\/tomaskalabis.com\/wordpress\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2021\/12\/vmware-vsphere-logo.png\",\"datePublished\":\"2023-11-28T18:50:36+00:00\",\"dateModified\":\"2023-11-28T18:53:19+00:00\",\"author\":{\"@id\":\"https:\/\/tomaskalabis.com\/wordpress\/#\/schema\/person\/8e7e83f618a561ed3734a38cef4cf1d6\"},\"description\":\"Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again.\",\"breadcrumb\":{\"@id\":\"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/#breadcrumb\"},\"inLanguage\":\"cs\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"cs\",\"@id\":\"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/#primaryimage\",\"url\":\"https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2021\/12\/vmware-vsphere-logo.png\",\"contentUrl\":\"https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2021\/12\/vmware-vsphere-logo.png\",\"width\":166,\"height\":166},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/tomaskalabis.com\/wordpress\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again.\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/tomaskalabis.com\/wordpress\/#website\",\"url\":\"https:\/\/tomaskalabis.com\/wordpress\/\",\"name\":\"tomaskalabis.com\",\"description\":\"my personal blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/tomaskalabis.com\/wordpress\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"cs\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/tomaskalabis.com\/wordpress\/#\/schema\/person\/8e7e83f618a561ed3734a38cef4cf1d6\",\"name\":\"Tomas Kalabis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"cs\",\"@id\":\"https:\/\/tomaskalabis.com\/wordpress\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/9f7e4796b38d5720e8a07b918f423311?s=96&d=retro&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/9f7e4796b38d5720e8a07b918f423311?s=96&d=retro&r=g\",\"caption\":\"Tomas Kalabis\"},\"sameAs\":[\"https:\/\/x.com\/tomaskalabis\"],\"url\":\"https:\/\/tomaskalabis.com\/wordpress\/author\/kalabis\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again. - tomaskalabis.com","description":"Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/","og_locale":"cs_CZ","og_type":"article","og_title":"Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again. - tomaskalabis.com","og_description":"Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again.","og_url":"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/","og_site_name":"tomaskalabis.com","article_published_time":"2023-11-28T18:50:36+00:00","article_modified_time":"2023-11-28T18:53:19+00:00","og_image":[{"width":166,"height":166,"url":"https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2021\/12\/vmware-vsphere-logo.png","type":"image\/png"}],"author":"Tomas Kalabis","twitter_misc":{"Napsal(a)":"Tomas Kalabis","Odhadovan\u00e1 doba \u010dten\u00ed":"3 minuty"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/","url":"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/","name":"Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again. - tomaskalabis.com","isPartOf":{"@id":"https:\/\/tomaskalabis.com\/wordpress\/#website"},"primaryImageOfPage":{"@id":"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/#primaryimage"},"image":{"@id":"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/#primaryimage"},"thumbnailUrl":"https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2021\/12\/vmware-vsphere-logo.png","datePublished":"2023-11-28T18:50:36+00:00","dateModified":"2023-11-28T18:53:19+00:00","author":{"@id":"https:\/\/tomaskalabis.com\/wordpress\/#\/schema\/person\/8e7e83f618a561ed3734a38cef4cf1d6"},"description":"Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again.","breadcrumb":{"@id":"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/#breadcrumb"},"inLanguage":"cs","potentialAction":[{"@type":"ReadAction","target":["https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/"]}]},{"@type":"ImageObject","inLanguage":"cs","@id":"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/#primaryimage","url":"https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2021\/12\/vmware-vsphere-logo.png","contentUrl":"https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2021\/12\/vmware-vsphere-logo.png","width":166,"height":166},{"@type":"BreadcrumbList","@id":"https:\/\/tomaskalabis.com\/wordpress\/upgrading-vmware-vcenter-vcsa-7-0-3-to-8-0-2-fails-with-regenerate-certificates-for-sso-and-try-again\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/tomaskalabis.com\/wordpress\/"},{"@type":"ListItem","position":2,"name":"Upgrading VMware vCenter (VCSA) 7.0.3 to 8.0.2 fails with Regenerate certificates for SSO and try again."}]},{"@type":"WebSite","@id":"https:\/\/tomaskalabis.com\/wordpress\/#website","url":"https:\/\/tomaskalabis.com\/wordpress\/","name":"tomaskalabis.com","description":"my personal blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/tomaskalabis.com\/wordpress\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"cs"},{"@type":"Person","@id":"https:\/\/tomaskalabis.com\/wordpress\/#\/schema\/person\/8e7e83f618a561ed3734a38cef4cf1d6","name":"Tomas Kalabis","image":{"@type":"ImageObject","inLanguage":"cs","@id":"https:\/\/tomaskalabis.com\/wordpress\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/9f7e4796b38d5720e8a07b918f423311?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f7e4796b38d5720e8a07b918f423311?s=96&d=retro&r=g","caption":"Tomas Kalabis"},"sameAs":["https:\/\/x.com\/tomaskalabis"],"url":"https:\/\/tomaskalabis.com\/wordpress\/author\/kalabis\/"}]}},"jetpack_featured_media_url":"https:\/\/tomaskalabis.com\/wordpress\/wp-content\/uploads\/2021\/12\/vmware-vsphere-logo.png","_links":{"self":[{"href":"https:\/\/tomaskalabis.com\/wordpress\/wp-json\/wp\/v2\/posts\/7369"}],"collection":[{"href":"https:\/\/tomaskalabis.com\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tomaskalabis.com\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tomaskalabis.com\/wordpress\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/tomaskalabis.com\/wordpress\/wp-json\/wp\/v2\/comments?post=7369"}],"version-history":[{"count":2,"href":"https:\/\/tomaskalabis.com\/wordpress\/wp-json\/wp\/v2\/posts\/7369\/revisions"}],"predecessor-version":[{"id":7373,"href":"https:\/\/tomaskalabis.com\/wordpress\/wp-json\/wp\/v2\/posts\/7369\/revisions\/7373"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/tomaskalabis.com\/wordpress\/wp-json\/wp\/v2\/media\/7010"}],"wp:attachment":[{"href":"https:\/\/tomaskalabis.com\/wordpress\/wp-json\/wp\/v2\/media?parent=7369"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tomaskalabis.com\/wordpress\/wp-json\/wp\/v2\/categories?post=7369"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tomaskalabis.com\/wordpress\/wp-json\/wp\/v2\/tags?post=7369"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}