VCSA7.0访问提示no healthy upstream故障解决方案

该文章详细描述了如何通过SSH访问VSCA主机,检查并发现__MACHINE_CERT证书已过期,然后使用vSphereCertificateManager重新生成并替换证书,最后确认新证书的有效期并重启VSCA来解决vCenter网页显示nohealthyupstream的问题。
摘要由CSDN通过智能技术生成

打开vCenter网页显示no healthy upstream报错,报错如图

 解决办法:

1、使用SSH访问VSCA主机。

2、输入如下命令,检查证书有效期,发现__MACHINE_CERT证书到期。

for i in $(/usr/lib/vmware-vmafd/bin/vecs-cli store list); do echo STORE $i; sudo /usr/lib/vmware-vmafd/bin/vecs-cli entry list --store $i --text | egrep "Alias|Not After"; done
STORE MACHINE_SSL_CERT
Alias :	__MACHINE_CERT
            Not After : May 13 19:13:28 2023 GMT
STORE TRUSTED_ROOTS
Alias :	6a23dc81223746a515a85e9cca52764b2e3abb00
            Not After : May  8 07:13:28 2031 GMT
STORE TRUSTED_ROOT_CRLS
Alias :	64349b77335ceb78c86e429d2bc5592bd946d81f
STORE machine
Alias :	machine
            Not After : May  8 07:13:28 2031 GMT
STORE vsphere-webclient
Alias :	vsphere-webclient
            Not After : May  8 07:13:28 2031 GMT
STORE vpxd
Alias :	vpxd
            Not After : May  8 07:13:28 2031 GMT
STORE vpxd-extension
Alias :	vpxd-extension
            Not After : May  8 07:13:28 2031 GMT
STORE hvc
Alias :	hvc
            Not After : May  8 07:13:28 2031 GMT
STORE data-encipherment
Alias :	data-encipherment
            Not After : May  8 07:13:28 2031 GMT
STORE APPLMGMT_PASSWORD
STORE SMS
Alias :	sms_self_signed
            Not After : May 13 07:19:47 2031 GMT
STORE wcp
Alias :	wcp
            Not After : May  8 07:13:28 2031 GMT

3、执行如下命令重新生成证书。

/usr/lib/vmware-vmca/bin/certificate-manager
		 _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ 
		|                                                                     |
		|      *** Welcome to the vSphere 7.0 Certificate Manager  ***        |
		|                                                                     |
		|                   -- Select Operation --                            |
		|                                                                     |
		|      1. Replace Machine SSL certificate with Custom Certificate     |
		|                                                                     |
		|      2. Replace VMCA Root certificate with Custom Signing           |
		|         Certificate and replace all Certificates                    |
		|                                                                     |
		|      3. Replace Machine SSL certificate with VMCA Certificate       |
		|                                                                     |
		|      4. Regenerate a new VMCA Root Certificate and                  |
		|         replace all certificates                                    |
		|                                                                     |
		|      5. Replace Solution user certificates with                     |
		|         Custom Certificate                                          |
		|         NOTE: Solution user certs will be deprecated in a future    |
		|         release of vCenter. Refer to release notes for more details.|
		|                                                                     |
		|      6. Replace Solution user certificates with VMCA certificates   |
		|                                                                     |
		|      7. Revert last performed operation by re-publishing old        |
		|         certificates                                                |
		|                                                                     |
		|      8. Reset all Certificates                                      |
		|_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _|
Note : Use Ctrl-D to exit.
Option[1 to 8]: 3

Please provide valid SSO and VC privileged user credential to perform certificate operations.
Enter username [Administrator@vsphere.local]:administrator@XX.com
Enter password:
certool.cfg file exists, Do you wish to reconfigure : Option[Y/N] ? : y

Press Enter key to skip optional parameters or use Previous value.

Enter proper value for 'Country' [Previous value : XX] : 

Enter proper value for 'Name' [Previous value : XX] : XXXX

Enter proper value for 'Organization' [Previous value : XX] : XXX

Enter proper value for 'OrgUnit' [Previous value : IT] : 

Enter proper value for 'State' [Previous value : GD] : 

Enter proper value for 'Locality' [Previous value : SZ] : 

Enter proper value for 'IPAddress' (Provide comma separated values for multiple IP addresses) [optional] : 10.1.248.200

Enter proper value for 'Email' [Previous value : XXXX] : 

Enter proper value for 'Hostname' (Provide comma separated values for multiple Hostname entries) [Enter valid Fully Qualified Domain Name(FQDN), For Example : example.domain.com] : XXXX

Enter proper value for VMCA 'Name' :XXX

You are going to regenerate Machine SSL cert using VMCA
Continue operation : Option[Y/N] ? : y
Status : 100% Completed [All tasks completed successfully]

4、参考步骤2重新检查证书有效期,最后重启VSCA即可

for i in $(/usr/lib/vmware-vmafd/bin/vecs-cli store list); do echo STORE $i; sudo /usr/lib/vmware-vmafd/bin/vecs-cli entry list --store $i --text | egrep "Alias|Not After"; done
STORE MACHINE_SSL_CERT
Alias :	__MACHINE_CERT
            Not After : May 23 08:45:22 2025 GMT
STORE TRUSTED_ROOTS
Alias :	6a23dc81223746a515a85e9cca52764b2e3abb00
            Not After : May  8 07:13:28 2031 GMT
STORE TRUSTED_ROOT_CRLS
Alias :	1e1215514e59417072d1522937e387a693a67af8
STORE machine
Alias :	machine
            Not After : May  8 07:13:28 2031 GMT
STORE vsphere-webclient
Alias :	vsphere-webclient
            Not After : May  8 07:13:28 2031 GMT
STORE vpxd
Alias :	vpxd
            Not After : May  8 07:13:28 2031 GMT
STORE vpxd-extension
Alias :	vpxd-extension
            Not After : May  8 07:13:28 2031 GMT
STORE hvc
Alias :	hvc
            Not After : May  8 07:13:28 2031 GMT
STORE data-encipherment
Alias :	data-encipherment
            Not After : May  8 07:13:28 2031 GMT
STORE APPLMGMT_PASSWORD
STORE SMS
Alias :	sms_self_signed
            Not After : May 13 07:19:47 2031 GMT
STORE wcp
Alias :	wcp
            Not After : May  8 07:13:28 2031 GMT
STORE BACKUP_STORE
Alias :	bkp___MACHINE_CERT
            Not After : May 13 19:13:28 2023 GMT
Alias :	bkp_machine
            Not After : May  8 07:13:28 2031 GMT
Alias :	bkp_vsphere-webclient
            Not After : May  8 07:13:28 2031 GMT
Alias :	bkp_vpxd
            Not After : May  8 07:13:28 2031 GMT
Alias :	bkp_vpxd-extension
            Not After : May  8 07:13:28 2031 GMT
Alias :	bkp_hvc
            Not After : May  8 07:13:28 2031 GMT
Alias :	bkp_wcp
            Not After : May  8 07:13:28 2031 GMT

参考官网链接:

VMware Knowledge Base

vcsa7.0的安装教程如下: 1. 首先,需要挂载vcsa7.0的镜像文件,可以使用软碟通将镜像写入U盘或光盘。 2. 打开镜像文件,并选择"install"打开安装程序。 3. 在安装程序中选择"安装",vcsa7.0提供了其他选项供选择。 4. 勾选"我接受许可协议条款"。 5. 指定vcsa7.0部署到ESXi主机或VC。如果出现报错,请参考相关博客解决"无法获取目标服务器证书的SSL指纹"。 6. 出现证书警告时,选择"是"。 7. 配置vcsa7.0虚拟机名称以及root密码。 8. 选择合适的部署大小,根据实际物理机情况选择微型或其他大小。注意内存、CPU和磁盘的配置是否足够。 9. 选择vcsa7.0虚拟机存储。 10. 配置虚拟机网络。输入系统名称和域名(请将问号替换为实际的域名),并输入IP地址、子网掩码、网关和DNS信息。 11. 确认第一阶段参数,并等待部署完成。部署时间取决于物理服务器性能。 12. 完成第一阶段部署后,打开浏览器,输入ESXi的IP地址,再输入ESXi管理员界面的地址(通常是https://IP地址:5480),进入第二阶段的安装。 请根据以上步骤逐步进行vcsa7.0的安装。<span class="em">1</span><span class="em">2</span><span class="em">3</span> #### 引用[.reference_title] - *1* *3* [服务器虚拟化安装VCSA7.0(vCenterv Server Appliance 7.0)](https://blog.csdn.net/qq_45848361/article/details/111030505)[target="_blank" data-report-click={"spm":"1018.2226.3001.9630","extra":{"utm_source":"vip_chatgpt_common_search_pc_result","utm_medium":"distribute.pc_search_result.none-task-cask-2~all~insert_cask~default-1-null.142^v93^chatsearchT3_1"}}] [.reference_item style="max-width: 50%"] - *2* [VMware vCenter Server 7.0 完整安装教程](https://blog.csdn.net/baidu_39512534/article/details/128031457)[target="_blank" data-report-click={"spm":"1018.2226.3001.9630","extra":{"utm_source":"vip_chatgpt_common_search_pc_result","utm_medium":"distribute.pc_search_result.none-task-cask-2~all~insert_cask~default-1-null.142^v93^chatsearchT3_1"}}] [.reference_item style="max-width: 50%"] [ .reference_list ]
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值