Lstool Reregister Failed

3 views
Skip to first unread message

Luisa Rodocker

unread,
Aug 5, 2024, 7:22:51 AM8/5/24
to sertiogletro
Istarted the process of upgrading our vCenter appliance from 6.7 to 7.0. We have not yet replaced our Dell Equallogic SAN and the storage plugin still uses flash. So, when I saw that 7.0 doesn't support flash, I went through the process of cancelling the upgrade and it rolled back to 6.7. I'm trying to log into the appliance in the web browser so that I can check for updates. Once I sign in, I see what's shown in the attachment. What options do I have?

After migrating a vcsa server to a new host by cloning and moving to a new host ( with a new IP) all the entities see within vcsa are either "disconnected" ( hosts and vms) or "inaccessible" ( datastores). All right click options on any entity is also greyed out


When I try to log in as root on the VMware Appliance Management web:5480 page using the IP address of the server, I receive the error. Unable to login, NOT the error Unable to authenticate user. I can successfully log in using the console with root credentials. Used a variety of browsers and validated security settings. Any ideas?


I recently downloaded the trial of VCSA 7U1a. I seem to be having issues with setting up the Server. I have tried the windows install to the ip address and the included OVF with no luck. Below are is the error I am getting with the OVF. I also have the logs from the windows install, But don't know what to look at specifically


VM is allocated 2 x Intel Core i7-10700, 11.7 GB memory. Its got a static IP and bridged to the local network which has a DNS server which I am confident is working because I can see the lookups and replies.


I've been attempting to configure vCenter v6.7u3 to use an openLDAP server as a SSO using LDAPS and in the process been unsuccessful. The main problem is that vCenter will establish a tls connection and verify the certificate signatures, but will then close the connection immediately.


With openssl s_client, I can connect to the port with the certificates I provide, but I can't find anything else that would be useful. I can also connect on LDAP:// as well, but I want to establish a TLS connection. Is there a particular way that the certificates should be made? I just want to get the LDAPS to work.


--> [context]zKq7AVECAAAAAGC34QASdnB4ZAAA4AArbGlidm1hY29yZS5zbwAAWCUbAP6dGAHu8VN2cHhkAAHu1VoBzsNjATdPoAGuOKACwO0BbGliYXV0aHpjbGllbnQuc28AAmkGAgLijQICxIUCAb3XngE6CVQBimhUARnGUgOQBQJsaWJjLnNvLjYAAaW+Ug==[/context]>


When applying a certificate using our Microsoft CA (I followed the VMware article/video on how to create a certiifcate template) to our vCenter (Windows) server, it fails and rolls back. The issue I'm getting is the same as the following discussion posted a few months back. However, there's no fix provided:certificate-manager 'lstool reregister' failed: 1 / VCSA Certificate Manager Option 1: Replace Machine SSL certificate with Custom Certificate


I would like to configure a backup from a VCSA 7.0 to to a FTPS-Server (running on a Windows Server). I've installed Bitvise SSH server application on this Windows server and FTPS enabled on port 21. I'v set up the whole certificate things - and it seams when I start a backup from the VCSA (VAMI -> Backup), then it stucks during TLS negotiation. The VCSA backup reports "General system error reported by backup server."


Before making the router switch I shut everything down, VMs, hosts, switches, Synology, modem. I set up the new pfSense box, set up the reservations to give the same address to everything and brought them back online in reverse.


Now when logging into the VCSA both hosts shows as not responding and all VMs show as disconnected. I try to connect the hosts but it fails before even trying to authenticate saying, "The host may not be available on the network, a network configuration problem may exist, or the management services on this host may not be responding." However, I can connect directly to the hosts.


Our vcenter is installed on a windows machine, it is not an appliance. We are on vCenter 6 version 3g. I know it is out of date, we are not in a position to update any of it. We currently have a new environment with updated software but it will be a few months as we migrate. Within our vcenter we also have NSX and VCD so we are cautious about doing anything cert related.


Currently we cannot log into our vsphere environment unless we role back the time to a date prior to 8/15, after changing the date and restarting the web service, we are able to log in. I know the location of the certificate manager application on the windows machine but we are unsure the best route to take dealing with these certs. Again, we do not want to use custom certs or redo root certs, we just need to extend these 4 certs to get everything working while we migrate to the new environment.


Anyone else notice that the release notes for VCSA 6.7 U3i (6.7.0.44200 build 16616482) are no where to be found? I find that odd, even though it's just Photon patches, there should be something detailing what's been patched and such.


I'm just trying the simplest thing - to run tomcat server located in vsphere-ui/server. It looks like being started successfully, but in the browser I'm getting the aforementioned message. I should note that I can access and log into the vCenter UI URL without any issues, the error only happens when I access the UI through local server. These are the messages I'm getting in the vsphere_client_virgo.log:


Trying a similar test to grant access worked right away detects the change right away but removing access doesn't get detected until the next day (I think I've seen a similar issue with nested groups and not detecting a change in membership in the past which I assume is related)


I'm starting the learning process on the VMWare platform with a home lab setup. ESXI 6.5 is installed on my server and I am able to successfully manage the system via the web interface. However, I'd like to explore some of the options present in the vCenter Server application. However, I'm unable to locate the correct download for this product.


Message: You either are not entitled or do not have permissions to download this product. Check with your My VMware Super User, Procurement Contact or Administrator. If you recently purchased this product thorugh VMware Store or through a third party, try downloading later.


So I can't access the VCSA using root as the password says it's incorrect. This seems to have happened after the upgrade from 6.5 - 6.7 but I really thought I had the right password but I'm willing to accept that there may have been a mistype when upgrading. Anyway I looked on line and there is a simple procedure to rest the root password by restarting VCSA, pressing "E" on the Photon splash screen then editing the GNU GRUB menu. All goes smoothly, confirms new password has been accepted but when I reboot it won't accept the password? I've tried this quite a few times each time choosing a different password but for some reason it just doesn't seem to work.


We cannot remove one crashed VMware host from our datacenter. We do not have any clusters configured. We do have a vDS. Other hosts are working fine and in production. Remove from inventory is greyed out in vCenter.


My apologies if this has been covered, but didn't get any results when searching for ADFS or OAuth. I recently upgraded to vCenter 7 and after a lot of troubleshooting, I was able to get the Identity Provider to integrate with my ADFS server. My issue is that the domain for my users UPN does not match the domain of my user. As an example, my domain is 'abc.local', but my user has the UPN 'us...@xyz.com'. When I try to login I have to provide a bogus username of 'us...@abc.local' because the vCenter login page doesn't recognize my 'us...@xyz.com' address. After that, I receive the error message: "Unable to login because you do not have permission on any vCenter Server systems connected to this client".


I have verified Single Sign On works correctly with a user of a UPN that matches the domain (e.g. us...@abc.local). I have tried changing my claim to output the UPN and Name ID as SAM-Acco...@abc.local without success. I have also tried using a completely different field with the attribute 'us...@abc.local' without success. I thought maybe some type of transform my be necessary, but my experience with ADFS is limited and my experience with OAuth is non-existent. Has anybody else run across this issue or is this a known limitation with vCenter?

3a8082e126
Reply all
Reply to author
Forward
0 new messages