- ESXi uses chain certificate. When trusting the primary hosts, the whole chain certificate is added to hbr db.
- However, when trying to find a target host to use, only the leaf certificate is sent to match. As the certificates are not matched, hbrsrv broker service does not trust the primary host.
- VLSR appliance stores the full ESXi certificate chain but only verifies against the leaf certificate during replication, which causes a trust mismatch and connection failure.
- Error seen in
/var/log/vmware/hbrsrv.log on the target vLR appliance:
2025-08-04T19:18:54.404Z error hbrsrv[1527800] [Originator@6876 sub=Main groupID=PING-GID-########-####-####-####-############ opID=hsl-0] [0] Thumbprint and certificate is not allowed to send replication data
- This is a known issue effecting vSphere Replication 9.0.4
- The vLR appliance is also effected if it has a certificate with a chain