How to update to new download repository URLs for patching and upgrade?
Public facing repository URLs and authentication mechanisms have changed to unique token based URLs. Each of the required URLs are now unique to each customer and no longer common, as a result re-configuration is required.
- Download the token from the Broadcom Support Portal by following the steps in VCF Authenticated downloads Configuration Update Instructions. If the tokens are known already, apply the same by following the below instructions.
<br> - Disable the default repositories and configure the repositories with the token
Note: Scripted method to update the URLs are available in Authenticated Download Configuration Update Script.- Log into vSphere client
- On the vSphere Client Home page, Navigate to Lifecycle Manager.
- Click 'settings' tab. Under 'settings' tab,
- Go to Administration → Patch Setup.
- Disable default vLCM URLs by clicking "Disable" button:
<br>
Notes:
On vCenter Server versions below 8.0 U1 - Update Manager DB needs to be reset every time before adding/modifying a new tokenized URL.
On vCenter Server versions 8.0 U1 onwards - It is recommended to reset Update Manager DB if the Sync Update mentioned in Step 9 fails.
<br>
<br>
Note: The default URLs cannot be removed and delete button will be greyed out, it can only be Disabled.
<br>
<br> - Add the below URLs one by one by clicking 'NEW':
<br>
New URLs:
https://dl.broadcom.com/<Download Token>/PROD/COMP/ESX_HOST/main/vmw-depot-index.xml
https://dl.broadcom.com/<Download Token>/PROD/COMP/ESX_HOST/addon-main/vmw-depot-index.xml
https://dl.broadcom.com/<Download Token>/PROD/COMP/ESX_HOST/iovp-main/vmw-depot-index.xml
https://dl.broadcom.com/<Download Token>/PROD/COMP/ESX_HOST/vmtools-main/vmw-depot-index.xml
<br>
Note: Replace <Download Token> with the actual downloaded token id.
<br> - Ensure to remove any of the old urls that are being replaced as leaving these will cause vCenter to continue to try and reach them resulting in errors.
- Restart update manager service from an SSH session to vCenter Server
<br>
service-control --restart vmware-updatemgr
<br> - Download the content by going to vSphere Client Home page → Lifecycle Manager and selecting "ACTIONS" → Updates → Sync updates.
<br>
Notes:
<br>- Wait for the Sync updates operation to complete before initiating the ESXi updates.
<br> - If vLCM/VUM is trying to download the VIBs using an "older/inactive token" or still using "hostupdate.vmware.com" even after updating the right token, reset the vLCM Database by following the KB Resetting the VMware Update Manager Database.
<br>
Following are couple of sample scenarios where vLCM DB Reset is required.
Example - 1: ESXi Patching is failing with below error message and the "<AuthenticationToken>" in the URL is an older token which is no more valid.
Cannot download VIB: https://dl.broadcom.com/<AuthenticationToken>/PROD/COMP/ESX_HOST/main/esx/vmw/vib20/vibDir/vibnameHere.vib. This might be because of network issues or the specified VIB does NOT exist or does NOT have a proper 'read' privilege set. Please make sure the specified VIB exists and is accessible from vCenter Server.
Example - 2: ESXi Patching is failing with below error message and vLCM is still using the old default URLhostupdate.vmware.comeven though those default URLs are disabled.
Cannot download VIB: Cannot download VIB 'https://hostupdate.vmware.com/software/VUM/PRODUCTION/main/esx/vmw/vib20/vibDir/vibnameHere.vib'. This might be because of network issues or the specified VIB does NOT exist or does NOT have a proper 'read' privilege set. Make sure the specified VIB exists and is accessible from vCenter Server.
- Wait for the Sync updates operation to complete before initiating the ESXi updates.
<br>
10. Follow the steps from Error: "The vCenter Server is not able to reach the specified URL" vCenter Server patching via VAMI fails to download the updates from online repositories to update VAMI URL