HCX Site Pairing is down post certificate renewal on HCX
search cancel

HCX Site Pairing is down post certificate renewal on HCX

book

Article ID: 399679

calendar_today

Updated On:

Products

VMware HCX VMware Cloud on AWS

Issue/Introduction

  • HCX Site Pairing is down and it shows the below error message :
    PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target


  • The HCX Site Pairing is configured using FQDN address in the "Remote HCX URL" field.
  • Confirm that you have no site pairing connectivity issues

  • You would observe the following log entries in the HCX Manager  : /common/logs/admin/web.log
    <timestamps> UTC [https-jsse-nio-127.0.0.1-8443-exec-6, Ent: HybridityAdmin, , TxId: TxId: ####-####] ERROR c.v.v.h.api.registration.CloudConfig- Unable to update site-pair: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target
    com.vmware.vchs.hybridity.adapters.https.UntrustedCertificateException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target

Environment

VMware HCX
HCX deployed on VMware Cloud on AWS

Cause

The HCX Manager certificate at the Cloud (Target) site was recently updated or replaced. As a result, site pairing is disrupted because the Source HCX Manager is not aware of the updated certificate.

Resolution

This issue can be resolved by following the steps outlined below. This procedure must be performed on your Source (On-Premises) HCX environment.

Additional Information