1) I think I find an issue :
On my lab, I have an existing Veeam Enterprise manager latest version (migrate from previous version) and I use vcenter 8 GA (no U2).
When I try to setup the vsphere plugin, I select the custom role I create on vcenter + portal administrator and then I try to install it.
EM say me it's installed but on vcenter I can see an error : certificate doesn't support digital signature key usage.
I tried to perform the exact same task but this time with a new Enterprise manager and it works perfectly.
=> The issue is related to my EM server and not configuration or vcenter.
I decide to compare both certificate and they are not the same.
So, I decide to follow the step on this documentation to renew the certificate on my working EM server : https://helpcenter.veeam.com/docs/backu ... ml?ver=120
To generate a self signed certificate from IIS and now, installation doesn't work anymore.
Conclusion :
On new installation, EM create a self signed certificate with different option than you have when you create it from the IIS manager.
If you can reproduce my issue that means the documentation is wrong about it. It's not possible to use IIS with generate self signed certificate for vsphere plugin to work.
PS : Difference I notice on the certificate :
Not working : usage = remote computer authentication + all issuance policies
Working : usage = all application policies + all issuance policies
2) If I understand how I have to manage permission on the new EM architecture :
I need to add on EM all vsphere roles assigned to the users I want to be able to use the plugin ?
Hope I will have some details about this issue
