"Self-signed certificate is expiring on <vCenter_server_hostname> Please renew the certificate before the expiration date to ensure proper functionality of storage providers." as shown below.for store in $(/usr/lib/vmware-vmafd/bin/vecs-cli store list | grep -v TRUSTED_ROOT_CRLS); do echo "[*] Store :" $store; /usr/lib/vmware-vmafd/bin/vecs-cli entry list --store $store --text | grep -ie "Alias" -ie "Not After";done;
This alert occurs when one or more SMS certificates within the vCenter Server SMS store approach the expiration date. An expired SMS certificate disrupts communication between the vCenter Server and the VASA provider.
Follow the below steps:
Reset to Green on the alarm action on vSphere client.If you are using vVols, the SMS (Storage Monitoring Service) certificate connects your storage array's VASA provider and vCenter. If this breaks, your vVols don't go offline (data continues to flow), but they become unmanageable (no snapshots, no migrations, no power-ons). Some issues you might see and the steps to fix them:
When you replace the SMS cert, the Storage Array (Unity/PowerStore) still expects the old thumbprint.
The Result: The VASA Provider may go Offline.
The Fix: Go into the PowerStore/Unity Manager and "Update" or "Refresh" the vCenter connection to accept the new certificate identity.
Sometimes, even after updating the array, vCenter refuses to reconnect to the VASA provider.
The Fix: You may need to Remove and Re-add the Storage Provider in the vSphere Client.
Warning: Please note that removing a VASA provider is non-disruptive to running VMs. It simply refreshes the management registration.
The ESXi hosts have a service called vvold that talks to the VASA provider. It caches the certificate of the VASA provider.
The Problem: If the VASA provider gets a new certificate (signed by your new vCenter SMS/Root), the ESXi host might reject it because it’s different from what’s in its cache.
The Symptom: VMs show as "Inaccessible" after a power cycle.
The Fix:
vSphere UI: Right-click Host > Certificates > Refresh CA Certificates.
vSphere UI: Right-click Host > Certificates > Renew Certificate.
Host CLI (Mandatory): SSH into the host and run the command : /etc/init.d/vvold ssl_reset && /etc/init.d/vvold restart
UI: Right-click Host > Storage > Rescan Storage.