Site Recovery Manager or vSphere Replication Appliance disconnects after updating vCenter Certificates
search cancel

Site Recovery Manager or vSphere Replication Appliance disconnects after updating vCenter Certificates

book

Article ID: 312784

calendar_today

Updated On:

Products

VMware Live Recovery

Issue/Introduction

Symptom:

  • After replacing an expired vCenter certificate (like an STS cert or Machine SSL cert) SRM or VRMS is not accessible from vCenter.

  • Authentication throws "A server error occurred Check the server logs for more details."

  • Site Recovery Page is not accessible using Site Recovery plugin after vCenter SSL certificate renewal
  • Error seen while accessing Site Recovery plugin - "com.vmware.vim.vmomi.core.exception.CertificateValidationException: Server certificate chain is not trusted and thumbprint verification is not configured".

    "There are no vCenter Server instances with installed vSphere Replication or Site Recovery Manager"


  • This is seen at vSphere Client > Click on the Menu (Hamburger symbol on the top left) > Site Recovery:

Environment

VMware Site Recovery Manager 8.x
VMware Live Site Recovery 9.x
VMware vSphere Replication 8.x, 9.x

Cause

  • The SRM appliance is no longer able to authenticate against the replaced vCenter certificate.

  • When a certificate changes on the vCenter side, the token that was previously given to SRM/VRMS becomes null and needs to be renewed.

Resolution

To resolve this issue perform the below steps:

  1. Perform a "Reconfigure" for the vCenter's registered SRM and VR appliances from their respective VAMI page(eg: https://SRM_IP:5480, https://VR_IP:5480):



  2. Log into vSphere Client > Click on the Menu (Hamburger symbol on the top left) > Site Recovery. Verify that the appliances show status as "OK" (as seen below) and click on OPEN Site Recovery:



  3. Power cycle the SRM and VRMS VMs (Shutdown the guest OS & power it ON) and follow step 1 and 2 again, if it doesn't show OK status still, then proceed ahead.

  4. On the Site Recovery Page, under Summary perform a site "Reconnect". This will ensure the two site are connected and working as expected after the vCenter's SSL certificate renewal: