"Certificate validation failed" warning after certificate renewal in VCF Operations.
search cancel

"Certificate validation failed" warning after certificate renewal in VCF Operations.

book

Article ID: 441138

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

In VMware Cloud Foundation (VCF) Operations, a vCenter adapter may enter a Warning or Object Down state. This occurs when the vCenter Server SSL certificate has been renewed or replaced manually, but the new certificate thumbprint has not been trusted by the adapter instance within the Operations UI.

State: Collecting
Status: Object Down
Message: Certificate validation failed

Data collection for the affected vCenter stops, impacting dashboards and capacity reporting.

 

Environment

VMware Cloud Foundation 

Cause

Aria Operations maintains a trust store for integrated endpoints. When a vCenter certificate is updated, the stored thumbprint no longer matches the one presented by the vCenter API, causing the SSL handshake to fail.

Resolution

  1. Log in to the VCF Operations UI with administrative privileges.
  2. Navigate to Administrator> Integrations > Accounts.
  3. Locate the vCenter Server adapter instance currently in the warning state.
  4. Click the vertical ellipsis (three dots) or the pencil icon and select Edit.
  5. Scroll to the bottom of the configuration window and click Validate Connection.
  6. A dialog box will appear displaying the new SSL certificate thumbprint. Review the details and click Accept to add the certificate to the trust store.
  7. Click Save to commit the changes.

Post-Validation: Within 5 minutes, the adapter state should transition to Collecting and the status to Data Receiving or OK.

Additional Information