NetApp HCI - Unable to push CA certificates and CRLs to host when adding a host
Applies to
- NetApp HCI
- vSphere running VVOLs
- SolidFire VASA
Issue
- When adding a ESXi host to an existing vSphere cluster using vCenter you get the following error:
A general system error occurred: Unable to push CA certificates and CRLs to host <hostName>
- This issue seems to occur if the vSphere cluster has a configured SolidFire VASA provider
- Error logs from /var/log/vvold.log shows
self signed certificate, using default 2023-04-02T10:08:11.480Z info vvold[2100120] [Originator@6876 sub=Default] VasaSession::Initialize url is empty 2023-04-02T10:08:11.480Z warning vvold[2100120] [Originator@6876 sub=Default] VasaSession::DoSetContext: Empty VP URL for VP (NetApp HCI NE)! 2023-04-02T10:08:11.480Z info vvold[2100120] [Originator@6876 sub=Default] Initialize: Failed to establish connectionhttps://11.250.25.111:8444/vasa/services/vasaService/version.xml 2023-04-02T10:08:11.480Z error vvold[2100120] [Originator@6876 sub=Default] Initialize: Unable to init session to VP NetApp HCI NE state: 0 2023-04-02T10:08:11.480Z error vvold[2099616] [Originator@6876 sub=IO.Http] User agent failed to send request; (null), N7Vmacore3Ssl18SSLVerifyExceptionE(SSL Exception: Verification parameters: --> PeerThumbprint: 13:09:10:A3:2C:BD:E4:E7:55:CB:D4:5E:34:5D:22:21:9B:6E:7A:0B --> ExpectedThumbprint: --> ExpectedPeerName: 11.250.25.111 --> The remote host certificate has these problems: --> * unable to get local issuer certificate, using default