Site Recovery Manager or vSphere Replication Appliance disconnects after updating vCenter Certificates
book
Article ID: 312784
calendar_today
Updated On:
Products
VMware Live Recovery
Issue/Introduction
Symptom:
After replacing an expired vCenter certificate (like an STS cert or Machine SSL cert) SRM or VRMS is not accessible from vCenter.
Authentication throws "A server error occurred Check the server logs for more details."
Site Recovery Page is not accessible using Site Recovery plugin after vCenter SSL certificate renewal
Error seen while accessing Site Recovery plugin - "com.vmware.vim.vmomi.core.exception.CertificateValidationException: Server certificate chain is not trusted and thumbprint verification is not configured".
"There are no vCenter Server instances with installed vSphere Replication or Site Recovery Manager"
This is seen at vSphere Client > Click on the Menu (Hamburger symbol on the top left) > Site Recovery:
Environment
VMware Site Recovery Manager 8.x
VMware Live Site Recovery 9.x VMware vSphere Replication 8.x, 9.x
Cause
The SRM appliance is no longer able to authenticate against the replaced vCenter certificate.
When a certificate changes on the vCenter side, the token that was previously given to SRM/VRMS becomes null and needs to be renewed.
Resolution
To resolve this issue perform the below steps:
Perform a "Reconfigure" for the vCenter's registered SRM and VR appliances from their respective VAMI page(eg: https://SRM_IP:5480, https://VR_IP:5480):
Log into vSphere Client > Click on the Menu (Hamburger symbol on the top left) > Site Recovery. Verify that the appliances show status as "OK" (as seen below) and click on OPEN Site Recovery:
Power cycle the SRM and VRMS VMs (Shutdown the guest OS & power it ON) and follow step 1 and 2 again, if it doesn't show OK status still, then proceed ahead.
On the Site Recovery Page, under Summary perform a site "Reconnect". This will ensure the two site are connected and working as expected after the vCenter's SSL certificate renewal: