Host-based backup of Nutanix AHV VMs.
Post Reply
caspar32
Influencer
Posts: 20
Liked: 10 times
Joined: Apr 04, 2024 12:47 am
Full Name: Kan Lin
Contact:

How the simple steps for Veeam when Nutanix PC replaces the https certificate with CA

Post by caspar32 »

Dears:

I just want to know if there are some simple steps for Veeam Nutanix PC replaces the https certificate with CA.

After we replaces the Nutanix PC https certificates with our internal certificate (Not using Nutanix self-signed certificate), we encountered the errors: The remote certificate was rejected by the provided RemoteCertificateValidationCallback.

Hope someone can have some ideas. We have opened the case: 07968318. But support provided a very complicated solution.

1. Disconnect Prism Central from VBR:
https://helpcenter.veeam.com/docs/vbahv ... html?ver=7


2. Add a Prism Element / standalone cluster to VBR:
https://helpcenter.veeam.com/docs/vbahv ... html?ver=7


3. Deploy the backup appliance to the cluster:
https://helpcenter.veeam.com/docs/vbahv ... html?ver=7


4. Once online, migrate to a Prism Central configuration by re-adding the Prism Central instance:
https://helpcenter.veeam.com/docs/vbahv ... html?ver=7
ronnmartin61
Veeam Software
Posts: 683
Liked: 266 times
Joined: Mar 07, 2016 3:55 pm
Full Name: Ronn Martin
Contact:

Re: How the simple steps for Veeam when Nutanix PC replaces the https certificate with CA

Post by ronnmartin61 »

@caspar32 generally speaking I believe you should be able to select the Prism Central instance under "Managed Servers" and "edit" going through the wizard once more to re-establish cert trust / connectivity. If that doesn't work then best to run the steps support has given you.
caspar32
Influencer
Posts: 20
Liked: 10 times
Joined: Apr 04, 2024 12:47 am
Full Name: Kan Lin
Contact:

Re: How the simple steps for Veeam when Nutanix PC replaces the https certificate with CA

Post by caspar32 »

Now we solved this problem followed by below procedure:
b. Remove the proxy from the VBR configuration (do not destroy the proxy VM):
c. Remove the Prism Central connection from the VBR console:
d. Re-add Prism Central using the FQDN and the same settings:
e. Reconnect the existing proxy

Hence, I would like a new [Feature Request] for simply the procedure.

I think it will be perfect if coding related improvement could be added when operates below:

Update Certificate Trust for the Cluster:
· In the Veeam Backup & Replication console, navigate to the Nutanix AHV infrastructure section.
· Right-click your Prism Central cluster and select Properties.
· Click Next through each page and then Finish. If prompted about the certificate, click Continue to accept and trust the new CA-signed certificate.

Thanks.
Kochkin
Veeam Software
Posts: 103
Liked: 48 times
Joined: Sep 18, 2014 10:10 am
Full Name: Nikolai Kochkin
Contact:

Re: How the simple steps for Veeam when Nutanix PC replaces the https certificate with CA

Post by Kochkin » 2 people like this post

Thank you fir the FR.
That is already an expected behavior for hypervisors. At least latest versions should update certificate information when you re-run cluster or prism central wizard. Earlier there could be some complexities caused by additional database on backup appliance; new versions do not have a backup appliance.
caspar32
Influencer
Posts: 20
Liked: 10 times
Joined: Apr 04, 2024 12:47 am
Full Name: Kan Lin
Contact:

Re: How the simple steps for Veeam when Nutanix PC replaces the https certificate with CA

Post by caspar32 » 1 person likes this post

Got it. We plan to upgrade to V13 maybe 4-6 months later.
Post Reply

Who is online

Users browsing this forum: No registered users and 1 guest