In VMware vCenter Server, the UI continues to display a "Certificate expiring soon" or "Certificate expired" alarm even after all certificates have been successfully replaced and verified.
vCert.py script confirms no expired certificates in VMDIR or VECS stores.The vCenter Server alarm state is stale. The internal alarm engine failed to automatically reconcile the state after the underlying certificate stores (VECS/VMDIR) were updated. This is a residual false positive reflecting the previous state of the environment.
To resolve this issue, manually reset the alarm state in the vCenter Server UI:
Note: If the alert re-triggers, generate a new vCenter Server support bundle and verify certificate status again by using the script provided in vCert - Scripted vCenter expired certificate replacement and following the directions outlined in the "Generate certificate report" section at the bottom of the knowledge article.
If the certificates listed are all valid and the alert still reports, please open a case with Broadcom Support and provide the collected vCenter log bundle. See Creating and managing Broadcom cases