“VMware vSphere Profile-Driven Storage Service health alarm” was triggered.
search cancel

“VMware vSphere Profile-Driven Storage Service health alarm” was triggered.

book

Article ID: 420835

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

  • In the vSphere Client, a VMware vSphere Profile-Driven Storage Service health alarm is displayed.

  • When you access the target vCenter Server via SSH and run the command “curl http://localhost:22000/sms/HealthStatus" a CertificateNearingExpiry message appears as shown below.
    <?xml version="1.0" encoding="UTF-8" standalone="yes"?><healthStatus schemaVersion="1.0" xmlns="http://www.vmware.com/cis/cm/common/jaxb/healthstatus"><status>YELLOW</status><message messageKey="com.vmware.vim.sms.CertificateNearingExpiry" defaultMessage="Self-signed certificate is expiring on {0}. Please renew the certificate before the expiration date to ensure proper functionality of storage providers."><param xsi:type="xs:string" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">[SMS certificate expiration date]</param></message></healthStatus>

Environment

vCenter Server 7.x

vCenter Server 8.x

Cause

The alarm is triggered because the SMS certificate is nearing its expiration.

Resolution

The issue is resolved by renewing the SMS certificate on the vCenter server.

Note: Ensure there is valid backup/offline snapshot of the VCSA prior to implementing the workaround. Refer to VMware vCenter in Enhanced Linked Mode pre-changes snapshot (online or offline) best practice 

Use the vCert tool to initiate the certificate replacement process.

  1. Select Option 3: Manage certificates → Select Option 5: SMS certificates → Replace SMS self-signed certificate

  2. Once the certificate is replaced successfully, return to the main menu or exit the script and run:

  3. Select Option 8: Restart services --> Select Option 1: Restart all VMware services.

  4. Confirm the SMS certificate is renewed successfully by navigating to: View certificate info → Select Option 5: SMS certificates.

Once the certificates are verified as renewed and valid, proceed to acknowledge and clear the alarm in the vSphere Client.

Additional Information

vCert - Scripted vCenter expired certificate replacement

If you are using vCenter HA to provide redundancy with multiple vCenter Servers, first destroy the VCHA configuration, then take snapshots and proceed with the certificate renewal steps.