VMware vSphere

 View Only
  • 1.  Look like problem with cetr after update

    Posted Apr 14, 2023 09:38 PM
      |   view attached

    We have updated vcenter from version 6.5 to 7.0.3K It seems that everything is fine, but there are inexplicable problems with the veeam. We periodically catch an error between veeam and vcenter (error handshake).

    From the side, the vcenter saw the following when we tried to extract the certificates.

    https://vcenter.______-.local/certs/download.zip 

    Maybe we have some problems with cetrs?



  • 2.  RE: Look like problem with cetr after update

    Posted Apr 14, 2023 11:03 PM

    Hi ,

    I recommend to perform all the below to checks for your vCenter certificate, also run the VDT to verify the overall health of vCenter.

    1. Checking Expiration of STS Certificate on vCenter Servers - Download the checksts python script.
      https://kb.vmware.com/s/article/7924

    2. Verify certificate expiration date - https://kb.vmware.com/s/article/82332
    - In case expired then regenerate Self-Signed certificate with https://kb.vmware.com/s/article/2112283

    3. 
    Run VDT tool to check the overall health on the vCenter - https://flings.vmware.com/vsphere-diagnostic-tool
    Guide - https://4sysops.com/archives/troubleshoot-vmware-using-vsphere-diagnostic-tool/ or HowTo: vSphere Diagnostic Tool | TechMyth



  • 3.  RE: Look like problem with cetr after update

    Posted Apr 18, 2023 07:14 PM

    STS Certificate not expired.

    Diagnostic tools showed these errors:

    kievokhmatdet_4-1681845441324.png

     

    kievokhmatdet_0-1681845334047.png

     

    kievokhmatdet_2-1681845204470.png

     



  • 4.  RE: Look like problem with cetr after update

    Posted Apr 24, 2023 04:39 PM

    And now I have new question.

    How resolve problem on screen 2. KB isnt usefull.

    LDAPs I dont use.



  • 5.  RE: Look like problem with cetr after update

    Posted Apr 19, 2023 09:49 AM

    In firefox I dont have this problem. It is look like problem in browsers



  • 6.  RE: Look like problem with cetr after update

    Posted Apr 19, 2023 09:52 AM

    usually firefox is the browser where i have all kind of certificate related problems. Great that you could pin it down to specific browsers.



  • 7.  RE: Look like problem with cetr after update
    Best Answer

    Broadcom Employee
    Posted Apr 26, 2023 09:34 AM

    I don't think it has anything to do with certs here. If the handshake error is just random and get's fixed by its own ; it could be due to sessions/connections  exhausted .
    Check https://kb.vmware.com/s/article/88264

     



  • 8.  RE: Look like problem with cetr after update

    Posted Apr 27, 2023 09:27 AM

    Yes. It is look like your are right.

    Two days ago we analized logs vcenter and found remote https connections exceed max allowed: 2048 and session closed.

    How to see with whom so many sessions are established? Because we don't want to just raise the number....