I have an expired VASA certificate con my vCenter, the provider is my local Dell Unity 580 storage, this is affecting my vVols which i cannot access on vCenter and they show as 'inaccessible'. My question is if I delete the already expired vasa certificate, will that affect running VMs on my vVols? So I can try adding/registering the new certificate.
Sort by:
Backup Critical VMs and Data: Before removing the expired certificate, ensure you have backups of any critical VMs or data on the affected vVols, in case there are complications.
Delete the Expired Certificate and Add the New One: After ensuring backups, you can delete the expired certificate and register the new VASA certificate. This should restore proper communication between vCenter and the Dell Unity storage, assuming all goes well.
Monitor the Environment: After replacing the certificate, closely monitor the vVols and the VMs running on them to ensure that they function as expected.
If you delete the expired VASA (vSphere API for Storage Awareness) certificate, it won't immediately affect your running VMs on the vVols. However, deleting it without re-establishing the connection (i.e., registering a new certificate) can cause issues when vCenter needs to communicate with the storage system to perform management tasks related to the vVols, such as creating snapshots, deploying new VMs, or performing storage migrations.
Here’s how the process typically works:
1. Running VMs: Running VMs on vVols should continue to operate normally because the VM data is already stored on the storage. The active operations are handled by the ESXi hosts directly, not through vCenter.
2. Management Operations: If the certificate is deleted and not replaced promptly, vCenter may lose the ability to manage vVols, which includes creating new VMs, cloning, snapshots, and other operations that rely on storage awareness through the VASA provider.
3. Solution: The recommended approach is to register the new certificate before deleting the old one to ensure a seamless transition. If the new certificate is properly registered, vCenter will continue to communicate with the Dell Unity storage without interruptions.
Action Plan:
- Before deleting the expired certificate, obtain and register the new VISA certificate.
- Ensure the new certificate is recognized by vCenter.
- Once you confirm that the vVols are accessible again through vCenter, you can safely delete the expired certificate.