Search the VMware Knowledge Base (KB)
View by Article ID

Upgrading to vCenter Server 5.1 fails with the error: Certificate already expired (2035413)

  • 26 Ratings


  • Installing vCenter Single Sign On fails
  • Cannot upgrade to vCenter Server 5.1
  • vCenter Server 5.1 Installer fails
  • Upgrading vCenter Server 5.1 fails while installing the Inventory service
  • vCenter Server installer reports the error:

    Error 29113. Wrong input - either a command line argument is wrong, a file cannot be found or the spec file doesn't contain the required information, or the clocks on the two systems are not synchronized. Check vm_ssoreg.log in system temporary folder for details.

  • In the vm_ssoreg.log file, located in the %TEMP% directory, you see the error:

    java.lang.IllegalArgumentException: Invalid solution certificate. Certificate already expired.


This issue occurs if the vCenter Server certificate expires.

To verify if the certificate has expired, check the certificate file specified in file.

Note: The file is located at C:\Program Files\VMware\Infrastructure\VirtualCenter Server\ssoregtool\.


This issue is resolved in VMware vCenter Server 5.1.0a, available at VMware Downloads. For more information, see the VMware vCenter Server 5.1.0a Release Notes.

If you are unable to upgrade, regenerate the expired certificates and then upgrade to vCenter Server 5.1.
To regenerate the expired certificates and upgrade to vCenter Server 5.1: 

Note: If the upgrade previously succeeded however the VirtualCenter Server service now fails to start , see vCenter Server Services hang on startup after upgrading to vCenter Server 5.1 (2035623) to recover from this situation.
  1. Open the file using a text editor.
  2. Find the location of rui.crt certificate file, which is specified under the [solutionUsers] section of the file.

    Note: In some cases, the file may have been removed after a failed installation. If the file is removed, the default location of the rui.crt file is C:\Documents and Settings\All Users\Application Data\VMware\VMware VirtualCenter\SSL\.

  3. After determining the location of the rui.crt file, run this command to see the expiration date and view the encryption bit used:

    $ openssl x509 -in rui.crt -noout -text

    Note: In case of an expired certificate, you see an output similar to:

    Not Before: Jul 28 11:03:38 2008 GMT
    Not After : Jul 28 11:03:38 2010 GMT

  4. If the certificate expires, update the certificates before upgrading to vCenter Server 5.1. To update certificates on vSphere 5.0 and vSphere 4.1, see the steps outlined inInstalling the intermediate certificate chain for vCenter Server 5.0 (2030422).
  5. Once the new certificates are regenerated, re-try the vCenter Server 5.1 upgrade.
  6. After the upgrade completes, reconnect all hosts.

See Also

Update History

11/13/2012 - Added resolved with link to download center

Request a Product Feature

To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.


  • 26 Ratings

Did this article help you?
This article resolved my issue.
This article did not resolve my issue.
This article helped but additional information was required to resolve my issue.

What can we do to improve this information? (4000 or fewer characters)

Please enter the Captcha code before clicking Submit.
  • 26 Ratings