VCF Operations loses connectivity with a vCenter Server in a VMware Cloud Foundation (VCF) environment. This issue displays the following symptoms:
Data Collection Failure: Metrics and monitoring data for the target vCenter Server do not update in VCF Operations.
Licensing Alerts: The vCenter Server displays as NOT_LICENSE_MANAGED_VCENTER in Licensing Management, which triggers license compliance alerts.
Validation Error: VCF Operations reports the error "Error trying to establish connection" when running Validate Connection against the vCenter Server.
/storage/log/vcops/log/adapters/VMwareAdapter/VMwareAdapter_####.log) displays SSL handshake exceptions:com.vmware.vim.vmomi.client.exception.SslException: javax.net.ssl.SSLHandshakeException: PKIX path building failedCaused by: javax.net.ssl.SSLHandshakeException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target java.lang.ClassCastException: class java.security.cert.PKIXReason cannot be cast to class java.security.cert.CertPathValidatorException$BasicReason
/storage/log/vcops/log/analytics-####.log) displays:[com.vmware.vcops.auth.task.VcDomainDataRefreshServer.getDomainsMap] - Exception while getting domainlist from vc: https://vcenter.example.com/sdk message: Exception while getting userDirectory, reason: Connecting to VC at https://vcenter.example.com/sdk failed.VCF Operations 9.x
vCenter Server 9.x
The SSL/TLS certificate of the target vCenter Server changes or renews, but the updated certificate or its issuing Certificate Authority (CA) chain does not exist in the VCF Operations Trusted Certificate store. The resulting broken trust relationship causes VCF Operations to terminate the connection during the SSL handshake, resulting in failures in both the Management Adapter and the VMware Adapter.
Import the updated vCenter Server certificate into the VCF Operations trust store to restore connectivity: