Summary
When executing an VMWare Inventory discovery from Enterprise Deployment Suite running on a Windows Server 2003 SP2 or above server you may receive the following error if the VMWare instance you are querying is using a self-signed SSL certificate.Symptoms
When executing an VMWare Inventory discovery from Enterprise Deployment Suite running on a Windows Server 2003 SP2 or above server you may receive the following error if the VMWare instance you are querying is using a self-signed SSL certificate:
Failure reason:
- Failed to connect to the VMware Infrastructure server. VMware services may not be running on the machine, or may be running on a different port.
Errors:
- One or more errors were encountered while retrieving a Secure Sockets Layer (SSL) certificate from the server: Server's SSL certificate is invalid.
- In fsend call to WinHttpSendRequest: A security error occurred (12175)
- An error occured in HTTP processing
- Failed to retrieve contents from web service https://<SERVER_NAME>:443/sdk
Cause
Microsoft security update 2661254 (http://support.microsoft.com/kb/2661254) updates the minimum acceptable certificate key length to 1024 bit. VMWare self-signed certificates are 512bit and therefore will be rejected by all systems that have had this update applied.Resolution
A. Install and configure a 3rd Party CA or Enterprise CA certificate 1024bit or greater on each VMWare server.
B. Configure the Enterprise Deployment Server to allow certificates less than 1024 bit.
Resolution A: Refer to your VMWare documentation as to how to install a 3rd Party CA certificate.
Resolution B:
1. Logon to the Enterprise Deployment Suite Server with Local Administrator credentials;
2. Open a command prompt and execute:
Certutil -setreg chain\EnableWeakSignatureFlags 8
Certutil -setreg chain\WeakSignatureLogDir "c:\Temp\Under1024KeyLog"
The log directory can be locate anywhere on the server, just make sure that the folder exists before executing the command.
3. Re-execute the VMWare Inventory task to verify connectivity.
Please refer to Microsoft KB article for more information: http://support.microsoft.com/kb/2661254
Related Articles
Video: Update the SSL Certificate for Snow Inventory Server 309Number of Views Troubleshooting VMware discovery and inventory gathering 330Number of Views AddVDIGroups inventory import step may fail with error when importing data from multiple VMware Horizon connections that h… 4Number of Views Inventory import and license reconcile timeouts 36Number of Views VMware stand-alone inventory agent esxquery.exe for FlexNet Manager Suite & Flexera One ITAM 121Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Revenera Assistant
Case id: 00001065
Activity: Status change: 2 hours ago