This article explains the resolution for SSL certificate thumbprint mismatches occurring in VMware Live Site Recovery (formerly Site Recovery Manager) after replacing or rotating vCenter Server Machine SSL certificates. These mismatches result in SSL handshake failures during mutual authentication between components.
com.vmware.vim.vmomi.core.exception.CertificateValidationException. Server certificate chain is not trusted and thumbprint verification is not configured."Unable to connect to Lookup Service at https:/hostname/443/lookupservice/sdk. Reason: javax.net.ssl.SSLException: Certificate thumbprint mismatch."dr.log file on the vSphere Replication appliance (or VMware Live Site Recovery) certificate thumbprint mismatch error is seen:javax.net.ssl.SSLException: Certificate thumbprint mismatch.com.vmware.srm.client.topology.impl.vmomi.TokenProvider$AuthenticationTokenNotAvailable: No authentication token available for SSO Server at 'https://####/sts/STSService/vsphere.local'"This issue typically occurs after the Machine SSL certificate on the vCenter Server is replaced or rotated.Because SRM and vSphere Replication cache specific vCenter certificate thumbprints in their local trust stores, any change to the vCenter certificate renders these stored thumbprints invalid. This mismatch ultimately causes SSL handshake failures during mutual authentication
Validation of dr.log in vSphere Replication appliance (or from VMware Live Site Recovery) reports below.
[srm-reactive-thread-24966] WARN com. vmware.srm.client. infrastructure.http. BaseAsyncController #### - Request for path 'webssologin' failed.com.vmware.srm.client.topology.impl.vmomi.TokenProvider$AuthenticationTokenNotAvailable: No authentication token available for SSO Server at 'https://<####>/sts/STSService/vsphere.localSuppressed: com. vmware. vim. vmomi. client. exception. SslException: Unable to connect to SSO Management Server at https://<####>/o-adminserver/sdk/vsphere. local. Reason: javax.net.ssl. SSLException: Certificate thumbprint mismatch.at com. vmware. vim. vmomi. client. common. impl. ResponseImpl. setError (ResponseImpl. java: 265)Caused by: javax.net.ssl. SSLException: Certificate thumbprint mismatch.2026-07-08T07:00:55.669-04:00 warning drconfig[01111] [SRM@6876 sub=IO.Connection opID=####] Failed to SSL handshake; SSL(<io_obj p:0x00007f299c001ce0, h:15, <TCP '##### : ####'>, <TCP '##### : 443'>>), e: 167772294(certificate verify failed (SSL routines)), duration: 3msec2026-07-08T07:00:55.669-04:00 warning drconfig[01111] [SRM@6876 sub=HttpConnectionPool-000000 opID=######] Failed to get pooled connection; <cs p:###, TCP:######:443>, SSL(<io_obj p:##### h:15, <TCP '#####: ####'>, <TCP '####>>), duration: 5msec, N7Vmacore3Ssl18SSLVerifyExceptionE(SSL Exception: Verification parameters:--> PeerThumbprint: ######--> ExpectedThumbprint: #####--> ExpectedPeerName: #######
Follow these steps to reconfigure the appliances and restore the trust relationship:
https://####:5480).https://####:5480).To download specific releases, see Download Broadcom Products and Software.
To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.