Resolve SSL Certificate Thumbprint Mismatch in Site Recovery Manager after vCenter Certificate Replacement
search cancel

Resolve SSL Certificate Thumbprint Mismatch in Site Recovery Manager after vCenter Certificate Replacement

book

Article ID: 320615

calendar_today

Updated On:

Products

VMware Live Recovery VMware vCenter Server

Issue/Introduction

This article explains the resolution for SSL certificate thumbprint mismatches occurring in VMware Live Site Recovery (formerly Site Recovery Manager) after replacing or rotating vCenter Server Machine SSL certificates. These mismatches result in SSL handshake failures during mutual authentication between components.

Symptoms:

  • In the vCenter UI this error is displayed : "com.vmware.vim.vmomi.core.exception.CertificateValidationException. Server certificate chain is not trusted and thumbprint verification is not configured."
  • In the Site Recovery UI, when attempting to establish a site pair: "Unable to connect to Lookup Service at https:/hostname/443/lookupservice/sdk. Reason: javax.net.ssl.SSLException: Certificate thumbprint mismatch."
  • In the dr.log file on the vSphere Replication appliance (or VMware Live Site Recovery) certificate thumbprint mismatch error is seen:
    "javax.net.ssl.SSLException: Certificate thumbprint mismatch.
    com.vmware.srm.client.topology.impl.vmomi.TokenProvider$AuthenticationTokenNotAvailable: No authentication token available for SSO Server at 'https://####/sts/STSService/vsphere.local'"

Environment

  • VMware Live Recovery 9.x
  • VMware Site Recovery Manager 8.x
  • vSphere Replication 9.x

Cause

This issue typically occurs after the Machine SSL certificate on the vCenter Server is replaced or rotated.Because SRM and vSphere Replication cache specific vCenter certificate thumbprints in their local trust stores, any change to the vCenter certificate renders these stored thumbprints invalid. This mismatch ultimately causes SSL handshake failures during mutual authentication

  • Validation of dr.log in vSphere Replication appliance (or from VMware Live Site Recovery) reports below. 

    [srm-reactive-thread-24966] WARN com. vmware.srm.client. infrastructure.http. BaseAsyncController #### - Request for path 'webssologin' failed.com.vmware.srm.client.topology.impl.vmomi.TokenProvider$AuthenticationTokenNotAvailable: No authentication token available for SSO Server at 'https://<####>/sts/STSService/vsphere.local
    Suppressed: com. vmware. vim. vmomi. client. exception. SslException: Unable to connect to SSO Management Server at https://<####>/
    o-adminserver/sdk/vsphere. local. Reason: javax.net.ssl. SSLException: Certificate thumbprint mismatch.
    at com. vmware. vim. vmomi. client. common. impl. ResponseImpl. setError (ResponseImpl. java: 265)
    Caused by: javax.net.ssl. SSLException: Certificate thumbprint mismatch.

  • Validation of drconfig.log reports certificate verification failed due to incorrect thumbprint. 

2026-07-08T07:00:55.669-04:00 warning drconfig[01111] [SRM@6876 sub=IO.Connection opID=####] Failed to SSL handshake; SSL(<io_obj p:0x00007f299c001ce0, h:15, <TCP '##### : ####'>, <TCP '##### : 443'>>), e: 167772294(certificate verify failed (SSL routine
s)), duration: 3msec
2026-07-08T07:00:55.669-04:00 warning drconfig[01111] [SRM@6876 sub=HttpConnectionPool-000000 opID=######] Failed to get pooled connection; <cs p:###, TCP:######:443>, SSL(<io_obj p:##### h:15, <TCP '#####
: ####'>, <TCP '####>>), duration: 5msec, N7Vmacore3Ssl18SSLVerifyExceptionE(SSL Exception: Verification parameters:
--> PeerThumbprint: ######
--> ExpectedThumbprint: #####
--> ExpectedPeerName: #######

Resolution

Follow these steps to reconfigure the appliances and restore the trust relationship:

  1. Reconfigure vSphere Replication:
  2. Reconfigure Site Recovery Manager:
  3. Reconnect Site Pair:
    • Access the vSphere Client and navigate to Site Recovery > Site Pairs.
    • Select the affected pair and click Reconnect to synchronize the new certificates across sites. See Reconfiguring and Breaking Site Pairs.
  4. Use lsdoctor (Optional):

Additional Information

To download specific releases, see Download Broadcom Products and Software.

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.