The issue is caused due to missing Subject Alternative Name entry in the solution user certificates. This can be validated using the new improved certificate management tool vCert - Scripted vCenter Expired Certificate Replacement for all certificate management/replacement workflow. This tool helps to replace certificates with VMCA signed as well as custom CA signed certificates.
To confirm the mismatch, follow the below steps:
vCert script on your vCenter server.administrator credentials.option 1 (Check current certificate status) from the menu.The script will perform a check, the output for solution users will show as "NO SAN"
Before proceeding with the steps below, take both a backup and a snapshot of the vCenter Server Appliance. If the vCenter is part of a Enhanced Linked Mode (ELM) replication setup, also take a backup or offline (powered off) snapshot of all replicating vCenter ELM nodes.
To resolve this issue,
Replace the solution users certificate using the new improved certificate management tool vCert - Scripted vCenter Expired Certificate Replacement for all certificate management/replacement workflow. This tool helps to replace certificates with VMCA signed as well as custom CA signed certificates.
vCert script on your vCenter server.administrator credentials. Select option 3 to manage certificates.option 2 to replace solution user certificates.service-control --stop --all && service-control --start --all