Tuesday 24 May 2016

Unable to get signed certificate for host

While trying to add ESXi host in vCenter 6, you may get below error.

Error -

A general system error occurred: Unable to get signed certificate for host: <HOSTNAME>. Error: Failed to connect to the remote host, reason = rpc _s_too_many_rem_connects (0x16c9a046).

Reason -

This error occurs if you have replaced SSL certificates of VMware vCenter Server using VMCA and made VMCA as an Intermediate Certificate Authority.

Solution -

Once you make VMCA as an intermediate Certificate authority, you need to wait for 24 hours to add new ESXi Host in vCenter.

This behavior is changed in VMware vCenter 6.0 Update 2 and later with the advanced setting vpxd.certmgmt.certs.minutesBefore

Login to vCenter server using Administrator credentials, Go to vCenter server settings and update key  vpxd.certmgmt.certs.minutesBefore value to 10.

Workaround -

You can wait for 24 hours to add new Host in vCenter server or Add ESXi Hosts in vCenter before making VMCA as an Intermediate CA

 

Thanks…!

1 comment:

  1. Hi There, Sorry for picking up this thread and asking a different question...but i have been unable to get any information anywhere regarding the similar error i am facing and wondering if you any any idea about how to fix it, appreciate your kind help:
    A general system error occurred: Unable to get signed certificate for host: . Error: Failed to connect to the remote host, reason = rpc _s_connects_rejected (0x16c9a042). (382312514).


    I am getting this when i try to add a newly installed ESXi 6.0u2 server to my vcenter.
    my vcenter and existing setup of 3 node esxi cluster was recently upgraded from 5.1 to v6.0u2 and everything is running fine on that.
    the vcenter is setup with embedded PSC and VMCA is the root CA for this environment. there i no microsoft or any other third party issues CA certs here.
    I am puzzled as to why would vcenter 6.0u2 with ePSC and VMCA being root would be unable to issue signed cert to this new esxi 6.0u2 server ???
    appreciate any inputs.
    Thanks
    Ravi
    (ravindra.rampuria@gmail.com)

    ReplyDelete