Issue: Logging in to the vSphere Client fails with the error: HTTP Status 400 – Bad Request Message BadRequest, Signing certificate is not valid or error: HTTP Status 503
data:image/s3,"s3://crabby-images/154ba/154ba1d2de7f1e1be6226dd82ea4260c294eb45e" alt=""
Steps:
- Download the attached fixsts.sh script from this article https://kb.vmware.com/s/article/76719 and upload to the impacted PSC or vCenter Server with Embedded PSC to the /tmp folder.
- If the connection to upload to the vCenter by the WINSCP client is rejected, run this from an SSH session to the vCenter: chsh -s /bin/bash
- Navigate to the /tmp directory: cd /tmp
- Run chmod +x fixsts.sh to make the file executable.
- Run ./fixsts.sh.
- Enter the password of the VC Local admin account "administrator@vsphere.local"
data:image/s3,"s3://crabby-images/9559a/9559a8384ae38abc55423769c9c05330267d9bed" alt=""
data:image/s3,"s3://crabby-images/92aa7/92aa7b46c3923c071879307fb86f6a202b858c2f" alt=""
- Now you successfully reset the STS Cert
- Restart services on all vCenters and/or PSCs in your SSO domain by using below commands: service-control --stop --all and service-control --start --all
- Login to the vCenter and verify the STS Cert if renewed
data:image/s3,"s3://crabby-images/6ab3b/6ab3b7c87b5e2e3fea1b7e33a633d94fbf72eb8c" alt=""
VMware KB Reference: https://kb.vmware.com/s/article/76719
Comments