VCDA Replication Jobs Fail with "Invalid or inaccessible datastore" After vCenter/ESXi Certificate replacement
search cancel

VCDA Replication Jobs Fail with "Invalid or inaccessible datastore" After vCenter/ESXi Certificate replacement

book

Article ID: 447486

calendar_today

Updated On:

Products

VMware Cloud Director

Issue/Introduction

After renewing self-signed certificates for vCenter and regenerating certificates for ESXi hosts, replication jobs in VCDA may fail with the following symptoms:

  • VCDA Interface: Replication jobs show a status of "Error".
  • Destination Site Error: Invalid or inaccessible datastore
  • Source Site Error: Replication state is reported as error.

Environment

VMware Cloud Director Availability 4.7.x

Cause

When vCenter or ESXi certificates are regenerated, the VCDA services (Replicator, Tunnel, Manager, and Cloud Services) lose their trusted connection to the vCenter Lookup Service.

Because the existing thumbprints in VCDA no longer match the new certificates, VCDA cannot securely query vCenter to locate datastores or manage replication traffic. This results in the "Invalid or inaccessible datastore" error as the service endpoint communication is broken.

Resolution

To resolve this issue, you must force VCDA to trust and register the new vCenter/Lookup Service certificate thumbprints across all affected appliances.

Update the Lookup Service registration in the VCDA management interfaces to register the new certificate thumbprint.

  1. Update the lookup service by following this document: Configure the services to accept the vCenter Server Lookup service certificate and optionally allow SSO
  2. Once trust is re-established, the jobs may require a manual trigger to clear the error state. Select the Replications, Click Actions > Sync (or Resume if they appear paused).