After certificate expiration the provider and tenant portals will still load. When navigating through the UI there will be no resources, certificates, vCenters, Organizations, or Cloud Cells returned. Pages that would normally be populated will be blank.
Multisite is configure in the environment.
Organizations and cells are not visible in the Cloud Director UI.
The UI remains in a "loading" state or displays blank pages for resources.
Browser developer tools show failed fanout API calls with SSL validation errors.
vcloud-container-debug.log contains similar errors:
javax.net.ssl.SSLHandshakeException: PKIX path building failed.Direct API calls will still return resources.
VMware Cloud Director 10.5.x
VMware Cloud Director 10.6.x
The issue is caused by a certificate trust mismatch. When a certificate is updated on a local site, the change is not automatically trusted by the other sites in the multisite association, or the local site's new certificate must be manually re-trusted within its own "Trusted Certificates" store for fanout API calls to succeed.
To restore visibility of organizations and cells, import and trust the certificate within the Cloud Director Provider UI:
It may be necessary to delete and recreate the multi-site configuration:
This behavior can also occur if the site is no longer deployed or available. Removing the site as detailed above will restore functionality.