{"id":855,"date":"2019-04-09T17:36:23","date_gmt":"2019-04-09T15:36:23","guid":{"rendered":"https:\/\/virtualguru.cz\/?p=855"},"modified":"2019-04-09T20:12:55","modified_gmt":"2019-04-09T18:12:55","slug":"vcenter-vami-certificate-error","status":"publish","type":"post","link":"https:\/\/virtualguru.cz\/en\/2019\/04\/09\/vcenter-vami-certificate-error\/","title":{"rendered":"vCenter VAMI certificate error"},"content":{"rendered":"<p>Pot\u00e9, co jsem\u00a0nahradil\u00a0certifik\u00e1t PSC certifika\u010dn\u00ed autority, st\u00e1le mi jeden certifik\u00e1t hl\u00e1sil neplatnost, resp. chybu.<\/p>\n<p>Konkr\u00e9tn\u011b se jednalo o certifik\u00e1t pou\u017e\u00edvan\u00fd na Appliance Management rozhran\u00ed. (https:\/\/<em>&lt;vCenter&gt;<\/em>:5480)<\/p>\n<p>Prohl\u00ed\u017ee\u010d nav\u00edc ozna\u010doval str\u00e1nky jako ned\u016fv\u011bryhodn\u00e9 d\u00edky HSTS, jeliko\u017e na stejn\u00e9 adrese se vyskytovaly 2 r\u016fzn\u00e9 certifik\u00e1ty. (Postup pro smaz\u00e1n\u00ed HSTS zde: <a href=\"https:\/\/www.thesslstore.com\/blog\/clear-hsts-settings-chrome-firefox\/\">https:\/\/www.thesslstore.com\/blog\/clear-hsts-settings-chrome-firefox\/<\/a>)<\/p>\n<p>Na\u0161el jsem na to n\u00e1sledn\u011b KB\u00a0<a href=\"https:\/\/kb.vmware.com\/s\/article\/2136693\">https:\/\/kb.vmware.com\/s\/article\/2136693<\/a>, kter\u00e9 to popisuje jako known bug ji\u017e od verze 6.0.<\/p>\n<p>Postup je velmi jednoduch\u00fd a navazuje tam kde jsme skon\u010dili po v\u00fdm\u011bn\u011b certifik\u00e1tu (viz. <a href=\"https:\/\/virtualguru.cz\/en\/2019\/04\/02\/nastaveni-vcenter-psc-jako-intermediate-autority\/\">Nastaven\u00ed vCenter PSC jako intermediate autority<\/a>).<\/p>\n<p>St\u00e1le budeme pot\u0159ebovat certifik\u00e1t, kter\u00fd n\u00e1m vygenerovala certifika\u010dn\u00ed autorita a certifik\u00e1t autority samotn\u00e9.<\/p>\n<p>Pokud ji\u017e nem\u00e1te spojen\u00fd certifik\u00e1t chain, tak jej znovu vytvo\u0159te. Pokud m\u00e1te, m\u016f\u017eete pou\u017e\u00edt st\u00e1vaj\u00edc\u00ed.<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"null\">cat vmca_issued_cert.cer &gt; root_signing_chain.cer\r\ncat ca.cert.pem &gt;&gt; root_signing_chain.cer<\/pre>\n<p>Nakop\u00edrujte vznikl\u00fd Chain do slo\u017eky &#8222;\/etc\/applmgmt\/appliance&#8220;<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"null\">cp root_signing_cert.cer \/etc\/applmgmt\/appliance\/ca.crt<\/pre>\n<p>n\u00e1sledn\u011b si otev\u0159ete soubor s konfigurac\u00ed VAMI pro editaci:<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"null\">vi \/opt\/vmware\/etc\/lighttpd\/lighttpd.conf<\/pre>\n<p>Kdo VI editor zn\u00e1, p\u0159id\u00e1 n\u00e1sleduj\u00edc\u00ed \u0159\u00e1dek do konfigurace:<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"null\">ssl.ca-file = \"\/etc\/applmgmt\/appliance\/ca.crt\"<\/pre>\n<p>Kdo VI editor nezn\u00e1, tak detailn\u00ed postup:<\/p>\n<ol>\n<li>Pro vyhled\u00e1n\u00ed ide\u00e1ln\u00edho um\u00edst\u011bn\u00ed:\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"null\">&lt;ESC&gt; \/ssl\\.<\/pre>\n<\/li>\n<li>P\u0159epnout do Insert mode\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"null\">&lt;I&gt;<\/pre>\n<\/li>\n<li>zapsat \u0159\u00e1dek s konfigurac\u00ed\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"null\">ssl.ca-file = \"\/etc\/applmgmt\/appliance\/ca.crt\"<\/pre>\n<\/li>\n<li>Ulo\u017eit a zav\u0159\u00edt editor\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"null\">&lt;ESC&gt; :x!<\/pre>\n<\/li>\n<\/ol>\n<p>Pak u\u017e jen restartovat VAMI slu\u017ebu<\/p>\n<pre class=\"EnlighterJSRAW\" data-enlighter-language=\"null\">\/etc\/init.d\/vami-lighttp restart<\/pre>\n<p>P\u0159ece jen prost\u0159ed\u00ed vypad\u00e1 l\u00e9pe kdy\u017e m\u00e1 zelen\u00e9 certifik\u00e1ty a nemus\u00edte opakovan\u011b v prohl\u00ed\u017ee\u010di schvalovat bezpe\u010dnostn\u00ed v\u00fdjimku.<\/p>","protected":false},"excerpt":{"rendered":"<p>Pot\u00e9, co jsem\u00a0nahradil\u00a0certifik\u00e1t PSC certifika\u010dn\u00ed autority, st\u00e1le mi jeden certifik\u00e1t hl\u00e1sil neplatnost, resp. chybu. Konkr\u00e9tn\u011b se jednalo o certifik\u00e1t pou\u017e\u00edvan\u00fd na Appliance Management rozhran\u00ed. (https:\/\/&lt;vCenter&gt;:5480)&#8230;<\/p>\n<div class=\"more-link-wrapper\"><a class=\"more-link\" href=\"https:\/\/virtualguru.cz\/en\/2019\/04\/09\/vcenter-vami-certificate-error\/\">Continue Reading<span class=\"screen-reader-text\">vCenter VAMI certificate error<\/span> <i class=\"fas fa-angle-right\"><\/i><\/a><\/div>","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"iawp_total_views":14,"footnotes":""},"categories":[3],"tags":[25,26,7,19],"class_list":["post-855","post","type-post","status-publish","format-standard","hentry","category-vsphere","tag-certificate","tag-ssl","tag-vcenter","tag-vcsa","entry"],"_links":{"self":[{"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/posts\/855","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/comments?post=855"}],"version-history":[{"count":6,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/posts\/855\/revisions"}],"predecessor-version":[{"id":863,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/posts\/855\/revisions\/863"}],"wp:attachment":[{"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/media?parent=855"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/categories?post=855"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/virtualguru.cz\/en\/wp-json\/wp\/v2\/tags?post=855"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}