{"id":3518,"date":"2018-07-18T10:27:18","date_gmt":"2018-07-18T08:27:18","guid":{"rendered":"https:\/\/vm.piszki.pl\/?p=3518"},"modified":"2018-07-18T10:27:18","modified_gmt":"2018-07-18T08:27:18","slug":"blad-dodania-do-vmware-ceip-server-chain-certificate-is-not-trusted-przy-zewnetrznym-psc","status":"publish","type":"post","link":"https:\/\/vm.piszki.pl\/?p=3518","title":{"rendered":"B\u0142\u0105d dodania do VMware CEIP &ndash; Server chain certificate is not trusted (przy zewn\u0119trznym PSC)"},"content":{"rendered":"<p align=\"justify\">W naszej konfiguracji (jako zasz\u0142o\u015b\u0107 po vSphere 5.5) mamy osobno serwer vCenter i osobno serwer PSC. Testuj\u0105c vSAN postanowili\u015bmy pod\u0142\u0105czy\u0107 si\u0119 pod program VMware CEIP ze wzgl\u0119du na rozszerzenie monitorowania klastra vSAN o odpytywanie VMware online. Niestety, pod\u0142\u0105czenie okaza\u0142o si\u0119 nie udane, po d\u0142u\u017cszym szukaniu przyczyny, okaza\u0142o si\u0119 \u017ce b\u0142\u0105d (jak zwykle) tkwi w certyfikacie. W logu virgo klienta vSphere (tak flex jak i html5) pokaza\u0142y si\u0119 nast\u0119puj\u0105ce b\u0142\u0119dy (Server certificate chain is not trusted and thumbprint doesn&#8217;t match):<\/p>\n<p><a class=\"thickbox\" href=\"https:\/\/vm.piszki.pl\/wp-content\/uploads\/2018\/07\/sso2.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border: 0px currentcolor; margin-right: auto; margin-left: auto; float: none; display: block; background-image: none;\" title=\"sso2\" src=\"https:\/\/vm.piszki.pl\/wp-content\/uploads\/2018\/07\/sso2_thumb.jpg\" alt=\"sso2\" width=\"564\" height=\"87\" border=\"0\" \/><\/a><\/p>\n<p><a class=\"thickbox\" href=\"https:\/\/vm.piszki.pl\/wp-content\/uploads\/2018\/07\/sso1.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border: 0px currentcolor; margin-right: auto; margin-left: auto; float: none; display: block; background-image: none;\" title=\"sso1\" src=\"https:\/\/vm.piszki.pl\/wp-content\/uploads\/2018\/07\/sso1_thumb.jpg\" alt=\"sso1\" width=\"561\" height=\"26\" border=\"0\" \/><\/a><\/p>\n<p><!--more--><\/p>\n<p align=\"justify\">Dodam, \u017ce w przypadku vCenter i PSC u\u017cywamy certyfikat\u00f3w podpisanych przez nasze w\u0142asne CA a VM CA funkcjonuje jako SubCA. Po sprawdzeniu okaza\u0142o si\u0119, ku naszemu zdziwieniu, \u017ce g\u0142\u00f3wny certyfikat SSO jest podpisany przez RSA Identity and Access Toolkit Root CA. Aby nie robi\u0107 wi\u0119kszego zamieszania, postanowili\u015bmy nie przeprowadza\u0107 regeneracji tego certyfikatu a jedynie sprawdzi\u0107 czy jest on obecny w zaufanym magazynie kluczy w vCenter.<\/p>\n<p><a class=\"thickbox\" href=\"https:\/\/vm.piszki.pl\/wp-content\/uploads\/2018\/07\/sso3.png\"><img loading=\"lazy\" decoding=\"async\" style=\"border: 0px currentcolor; margin-right: auto; margin-left: auto; float: none; display: block; background-image: none;\" title=\"sso3\" src=\"https:\/\/vm.piszki.pl\/wp-content\/uploads\/2018\/07\/sso3_thumb.jpg\" alt=\"sso3\" width=\"549\" height=\"192\" border=\"0\" \/><\/a><\/p>\n<p align=\"justify\">Okaza\u0142o si\u0119, \u017ce nie (i nie tylko on), na szcz\u0119\u015bcie wystarczy\u0142o odpowiedni klucz wyeksportowa\u0107 i doda\u0107 z poziomu klienta vSphere UI w sekcji Administracja \u2013&gt; Certificate Management.<\/p>\n<p><a class=\"thickbox\" href=\"https:\/\/vm.piszki.pl\/wp-content\/uploads\/2018\/07\/sso4.png\"><img loading=\"lazy\" decoding=\"async\" style=\"margin-right: auto; margin-left: auto; float: none; display: block; background-image: none;\" title=\"sso4\" src=\"https:\/\/vm.piszki.pl\/wp-content\/uploads\/2018\/07\/sso4_thumb.jpg\" alt=\"sso4\" width=\"542\" height=\"332\" border=\"0\" \/><\/a><\/p>\n<p align=\"justify\">Dzi\u0119ki temu prostemu trikowi uda\u0142o si\u0119 rozwi\u0105za\u0107 problem.<\/p>\n<p><a class=\"thickbox\" href=\"https:\/\/vm.piszki.pl\/wp-content\/uploads\/2018\/07\/sso5.png\"><img loading=\"lazy\" decoding=\"async\" style=\"border: 0px currentcolor; margin-right: auto; margin-left: auto; float: none; display: block; background-image: none;\" title=\"sso5\" src=\"https:\/\/vm.piszki.pl\/wp-content\/uploads\/2018\/07\/sso5_thumb.jpg\" alt=\"sso5\" width=\"413\" height=\"136\" border=\"0\" \/><\/a><\/p>\n<p><a class=\"thickbox\" href=\"https:\/\/vm.piszki.pl\/wp-content\/uploads\/2018\/07\/sso4.png\">\u00a0<\/a><\/p>\n<div style='text-align:left' class='yasr-auto-insert-visitor'><\/div>","protected":false},"excerpt":{"rendered":"<p>W naszej konfiguracji (jako zasz\u0142o\u015b\u0107 po vSphere 5.5) mamy osobno serwer vCenter i osobno serwer PSC. Testuj\u0105c vSAN postanowili\u015bmy pod\u0142\u0105czy\u0107 si\u0119 pod program VMware CEIP ze wzgl\u0119du na rozszerzenie monitorowania klastra vSAN o odpytywanie VMware online. Niestety, pod\u0142\u0105czenie okaza\u0142o si\u0119 &hellip; <a href=\"https:\/\/vm.piszki.pl\/?p=3518\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":1604,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"yasr_overall_rating":0,"yasr_post_is_review":"","yasr_auto_insert_disabled":"","yasr_review_type":"","footnotes":""},"categories":[36,48],"tags":[123,125,124,57],"class_list":["post-3518","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-analiza","category-drobne-poprawki","tag-ceip","tag-psc","tag-sso","tag-vcenter"],"yasr_visitor_votes":{"stars_attributes":{"read_only":false,"span_bottom":false},"number_of_votes":0,"sum_votes":0},"_links":{"self":[{"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=\/wp\/v2\/posts\/3518"}],"collection":[{"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3518"}],"version-history":[{"count":2,"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=\/wp\/v2\/posts\/3518\/revisions"}],"predecessor-version":[{"id":3520,"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=\/wp\/v2\/posts\/3518\/revisions\/3520"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=\/wp\/v2\/media\/1604"}],"wp:attachment":[{"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3518"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3518"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vm.piszki.pl\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3518"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}