Error Code: LCMVIDM71092Failed to trust load balancer's certificate. Ensure load balancer has proper root certificate or provide the root certificate chain as retry param 'vidmLBRootCertificateChain' and try again.Unable to fetch root/intermediate CA certificates from the certificate chain provided. Failed to trust vIDM load balancer certificate. Retry by providing the root or intermediate CA certificate chain
LCMVIDM71077 after replacing certificates on vIDM node(s)Error Code LCMVIDM71077Unable to trust load balancer's certificate. Refer to the log for additional details and retry. Error while getting login token from vIDM
var/log/vrlcm/vmware_vrlcm.log have the following error:####-##-## 19:03:08.778 ERROR [####-#-######-##] c.v.v.l.v.d.h.VidmInstallHelper - -- Exception occured while trusting certificatecom.vmware.vrealize.lcm.common.exception.LcmException: Error while trusting LB's certificate on the host <VIDMNODEFQDN>, failed with message : {"message":"Error installing custom certificate, refer logs for more details.","code":2,"success":false,"results":null,"resultObj":null,"fieldMessages":null,"redirectUrl":null} at com.vmware.vrealize.lcm.vidm.driver.helpers.VidmInstallHelper.trustCertificate(VidmInstallHelper.java:867) [#####-##########-######-#.12.#-########.jar!/:?] at com.vmware.vrealize.lcm.vidm.driver.helpers.VidmInstallHelper.trustCertificate(VidmInstallHelper.java:824) [#####-##########-######-#.12.#-########.jar!/:?] at com.vmware.vrealize.lcm.vidm.core.task.VidmTrustLBCertificateTask.execute(VidmTrustLBCertificateTask.java:139) [#####-##########-####-#.12.#-########.jar!/:?] at com.vmware.vrealize.lcm.automata.core.TaskThread.run(TaskThread.java:63) [#####-#############-####-#.12.#-########.jar!/:?] at java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source) [?:?] at java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source) [?:?] at java.lang.Thread.run(Unknown Source) [?:?]
/var/log/vrlcm/vmware_vrlcm.log shows below error related to Failed to establish ssl handshake with server VIDMNODEFQDN:84432026-01-06T07:10:52.738Z INFO vrlcm[1171] [pool-3-thread-12] [c.v.v.l.v.c.t.u.VidmInstallTaskUtil] -- Sleeping and retrying after 10000 milliseconds...2026-01-06T07:11:12.754Z ERROR vrlcm[1171] [pool-3-thread-12] [c.v.v.l.v.c.t.u.VidmInstallTaskUtil] -- Exception caught while handshake : java.net.SocketTimeoutException: Read timed out2026-01-06T07:11:12.754Z ERROR vrlcm[1171] [pool-3-thread-12] [c.v.v.l.v.c.t.u.VidmInstallTaskUtil] -- Failed to establish ssl handshake with server VIDMNODEFQDN:8443. Retrying for 59 minutes...2026-01-06T07:11:12.754Z INFO vrlcm[1171] [pool-3-thread-12] [c.v.v.l.v.c.t.u.VidmInstallTaskUtil] -- Sleeping and retrying after 10000 milliseconds...2026-01-06T07:11:17.161Z INFO vrlcm[1171] [http-nio-8080-exec-7] [c.v.v.l.s.n.s.NotificationServiceImpl] -- Authentication object is not null org.springframework.security.authentication.UsernamePasswordAuthenticationToken@: YXYXYXYX org.springframework.security.core.userdetails.User########: Username: ########; Password: YXYXYXYX Enabled: true; AccountNonExpired: true; credentialsNonExpired: true; AccountNonLocked: true; Granted Authorities: LCM_ADMIN; Credentials: [PROTECTED]; Authenticated: true; Details: org.springframework.security.web.authentication.WebAuthenticationDetails@957e: RemoteIpAddress: ###.#.#.#; SessionId: null; Granted Authorities: LCM_ADMIN2026-01-06T07:11:32.766Z ERROR vrlcm[1171] [pool-3-thread-12] [c.v.v.l.v.c.t.u.VidmInstallTaskUtil] -- Exception caught while handshake : java.net.SocketTimeoutException: Read timed out2026-01-06T07:11:32.766Z ERROR vrlcm[1171] [pool-3-thread-12] [c.v.v.l.v.c.t.u.VidmInstallTaskUtil] -- Failed to establish ssl handshake with server VIDMNODEFQDN:8443. Retrying for 59 minutes...2026-01-06T07:11:32.767Z INFO vrlcm[1171] [pool-3-thread-12] [c.v.v.l.v.c.t.u.VidmInstallTaskUtil] -- Sleeping and retrying after 10000 milliseconds...
This issue is likely caused by one of the following scenarios:
Create new certificates using SHA 256 as Signature Algorithm instead of rsassaPss.
VMware is aware of a known issue in versions 3.3.7. Please see the Workaround section for additional information.
chmod 660 /opt/vmware/horizon/workspace/webapps/ROOT/lb_rootca.pem