Error: Certificate expiring soon alert persists after replacement in vCenter Server
search cancel

Error: Certificate expiring soon alert persists after replacement in vCenter Server

book

Article ID: 446983

calendar_today

Updated On:

Products

VMware vCenter Server VCF Operations

Issue/Introduction

In VMware vCenter Server, the UI continues to display a "Certificate expiring soon" or "Certificate expired" alarm even after all certificates have been successfully replaced and verified.

  • Running the vCert.py script confirms no expired certificates in VMDIR or VECS stores.
  • The vCenter Server UI alert remains in a 'Warning' or 'Critical' state.
  • Manual refreshes of the browser do not clear the alert.

Environment

  • VMware vCenter Server 
  • VMware Cloud Foundation (VCF) 

Cause

The vCenter Server alarm state is stale. The internal alarm engine failed to automatically reconcile the state after the underlying certificate stores (VECS/VMDIR) were updated. This is a residual false positive reflecting the previous state of the environment.

Resolution

To resolve this issue, manually reset the alarm state in the vCenter Server UI:

  1. Log in to the vSphere Client with administrator privileges.
  2. Navigate to the vCenter Server object in the inventory.
  3. Click the Monitor tab and select Issues and Alarms > Triggered Alarms.
  4. Locate the "Certificate expiring soon" or "Certificate expired" alarm.
  5. Select the alarm and click Acknowledge.
  6. Click Reset to Green.
  7. Monitor the environment for 24 hours to ensure the alarm does not re-trigger.

Note: If the alert re-triggers, generate a new vCenter Server support bundle and verify certificate status again by using the script provided in vCert - Scripted vCenter expired certificate replacement  and following the directions outlined in the "Generate certificate report" section at the bottom of the knowledge article

If the certificates listed are all valid and the alert still reports, please open a case with Broadcom Support and provide the collected vCenter log bundle. See Creating and managing Broadcom cases

Additional Information