vmware-topologysvc fails to start on vCenter Server./var/log/vmware/vmon/vmon.log:YYY-MM-DDTHH:MM:SS.MSSZ Wa(03) host-#### <topologysvc> Service pre-start command's stderr: self._sslobj.do_handshake()YYY-MM-DDTHH:MM:SS.MSSZ Wa(03)+ host-#### ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate has expired (_ssl.c:1017)YYY-MM-DDTHH:MM:SS.MSSZ Er(02) host-#### <topologysvc> Service pre-start command failed with exit code 1.YYY-MM-DDTHH:MM:SS.MSSZ Wa(03) host-#### [ReadSvcSubStartupData] No startup information from topologysvc.This issue occurs when an expired Trusted Root or Intermediary certificate remains in the TRUSTED_ROOTS VECS store and the VMware Directory (vmdir).
Ensure a powered-off snapshot of the vCenter Server (and all nodes in the SSO domain if in ELM) is taken before proceeding Best practices for using VMware snapshots in the vSphere environment
root/usr/lib/vmware-vmafd/bin/vecs-cli entry list --store TRUSTED_ROOTS --text | grep -E "Alias|Not After|Subject Key Identifier"/usr/lib/vmware-vmafd/bin/vecs-cli force-refreshservice-control --start --allservice-control --status vmware-topologysvc