YYYY-MM-DDTHH:MM:SS warning vpxd[####] [Originator@6876 sub=IO.Connection opID=####] Failed to SSL handshake; SSL(...), e: 167772294(certificate verify failed (SSL routines))YYYY-MM-DDTHH:MM:SS warning vpxd[####] [Originator@6876 sub=HttpConnectionPool opID=####] Failed to get pooled connection; ... SSL Exception: Verification parameters:--> PeerThumbprint: AA:AA:AA:AA:AA:AA:AA:AA:AA:AA:AA:AA:AA:AA:AA:AA:AA:AA:AA:AA--> ExpectedThumbprint: BB:BB:BB:BB:BB:BB:BB:BB:BB:BB:BB:BB:BB:BB:BB:BB:BB:BB:BB:BB--> ExpectedPeerName: #######--> * self-signed certificate in certificate chain
/var/log/vmware/envoy-hgw/envoy-access.log
YYYY-MM-DDTHH:MM:SS info envoy[2580] [Originator@6876 sub=Default] YYYY-MM-DDTHH:MM:SS POST /hgw/host-####/vpxa HTTP/1.1 526 upstream_reset_before_response_started{remote_connection_failure|TLS_error:|268435581:SSL_routines:OPENSSL_internal:CERTIFICATE_VERIFY_FAILED:TLS_error_end} UF 6606 1696 - 90 - - - - - <ESXi_IP>:443
/var/log/vmware/envoy-hgw/envoy.log
YYYY-MM-DDTHH:MM:SS info envoy-hgw[####] [Originator@6876 sub=connection] [Tags: "ConnectionId":"#######"] remote address:<IP_Address>,TLS_error:|268435581:SSL routines:OPENSSL_internal:CERTIFICATE_VERIFY_FAILED-----BEGIN CERTIFICATE-----#################-----END CERTIFICATE-----
VMware vSphere ESXi 8.x
vCenter Server 8.x
From a shell session on the affected ESXi host:
openssl x509 -noout -text -in /etc/vmware/ssl/rui.crt -fingerprint | grep -E "Issuer|Fingerprint"
Against the intercepted certificate from envoy.log:
openssl x509 -noout -text -in /etc/vmware/ssl/intercepted-cert.crt -fingerprint | grep -E "Issuer|Fingerprint"
Review any third-party products (such as a firewall doing SSL inspection) that handle network traffic between the ESXi host and vCenter Server, and disable SSL/TLS inspection.