2V0-15.25 · Question #51
An administrator is tasked with replacing a VMware vCenter certificate in VMware Cloud Foundation (VCF) Operations with an external CA-signed certificate. The certificate import completes…
The correct answer is D. The server certificate was copied to the wrong field. When replacing certificates in VMware Cloud Foundation (VCF) Operations, the system performs strict certificate chain validation. The error shown: "Certificate chain validation failed due to 'Signature does not match'" indicates that VCF Operations attempted to validate the…
Question
An administrator is tasked with replacing a VMware vCenter certificate in VMware Cloud Foundation (VCF) Operations with an external CA-signed certificate. The certificate import completes successfully but when running the certificate replacement task, it fails with the following error:
Certificate replacement has failed...The Certificate Chain validation failed due to 'Signature does not match' What is the possible cause of this issue?
Options
- AThe Certificate Signing Request (CSR) included the IP address of the vCenter.
- BThe external CA is not trusted by VCF Operations.
- CThe external CA is not accessible to VCF Operations.
- DThe server certificate was copied to the wrong field.
How the community answered
(36 responses)- A6% (2)
- B11% (4)
- C3% (1)
- D81% (29)
Explanation
When replacing certificates in VMware Cloud Foundation (VCF) Operations, the system performs strict certificate chain validation. The error shown: "Certificate chain validation failed due to 'Signature does not match'" indicates that VCF Operations attempted to validate the presented certificate chain but detected that the server certificate did not correctly match the signing CA certificate. This occurs most commonly when the administrator pastes the server certificate and CA root/intermediate certificates into the wrong fields during import. VCF requires the certificate bundle to be uploaded in the correct format: Server certificate Server Certificate field Intermediate certificates Intermediate Chain field Root certificate Root CA field If the chain order is wrong or the server certificate is mistakenly placed in an intermediate or root CA field, the cryptographic signature validation fails. This exact failure mode is documented in VMware certificate replacement workflows.
Topics
Community Discussion
No community discussion yet for this question.