A certificate expiration alarm is visible in vCenter, referencing the VECS TRUSTED_ROOTS store.
This occurs in both standalone vCenter and VMware Cloud Foundation (VCF) environments when expired CA certificates remain in the trust store after a previous certificate renewal or replacement operation.
The vSphere Client displays the following error: Certificate(s) in VECS TRUSTED_ROOTS store has expired KB 385107
These leftover certificates do not affect day-to-day operations but generate persistent alarms. If left unresolved, they can cause validation failures during future certificate operations, upgrades, or VCF workflows.
Additional symptoms reported:
Prerequisites
Option A: Remove expired certificates using the vCert tool
./vCert.pyOption B: Remove expired certificates manually
vecs-cli and dir-cli commands.Additional steps for VMware Cloud Foundation environments
vCenter and SDDC Manager maintain independent trust stores. After removing expired certificates from vCenter, verify whether the same expired certificates exist in SDDC Manager.
Verification
Related articles: