Host name '<HCX-Cloud_IP>' does not match the certificate subject provided by the peer (CN=hcx.sddc-###-###.vmwarevmc.com, O="VMware, Inc", L=Palo Alto, ST=California, C=US)Remote HCX URL" field.Remote HCX URL" field. However, the new certificate on the target HCX Manager uses a Fully Qualified Domain Name (FQDN) as its Common Name (CN), resulting in a mismatch. This issue can be resolved by following the steps outlined below. This procedure must be performed on the Source (On-Premises) HCX environment.
HCX 443 UI > Infrastructure > Site Pairs/Site PairingEDIT CONNECTION" OR "EDIT SITE PAIR" option in the existing Site Pairing.Username' and 'Password' and click the “EDIT” button.IMPORT CERTIFICATE" button on the "Certificate Warning" popup.IMPORT CERTIFICATE" is not generated:If above does not work, export the certificate manually and import it over HCX Manager 9443 UI:
This solution should be regarded as a last option; however, it is generally unsuitable for the majority of clients who have existing.
If these steps do not resolve the issue, the Site Pairs (including the Service Mesh) may need to be deleted, and recreate the Site Pairing using the FQDN.
NOTE: Note the Service Mesh configuration details from Infrastructure > Interconnect so that the mesh can be recreated later.
Navigate to Infrastructure > Interconnect and select "Delete" for any Service Mesh that depends on the Site Pairing we need to replace
Importing Trusted Certificates from a Remote Site
Remote HCX URL" instead of an IP Address.