This article addresses an issue where both scheduled and manual backups initiated via the vCenter Server Management (VAMI) interface fail with an SSL certificate verification error. The VAMI page may also return a 503 error, and the applmgmt service fails to start.
Error Message:
[MainProcess:PID-#######] [BackupManager::main:BackupManager.py:645] ERROR: BackupManager encountered an exception: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: certificate has expired (_ssl.c:1007)
VMware vCenter Server
The issue is caused by expired CA certificates within the VMware Directory Service (vmdir). While the machine SSL certificate itself may appear valid, the expiration of the vmdir CA certificates prevents the applmgmt service from initializing properly, resulting in 503 errors and the failure of all backup operations (scheduled and manual).
To restore functionality, the expired CA certificates within vmdir must be replaced to restore the correct certificate chain.
Prerequisites:
Replacement Steps:
vCert tool to inspect and identify the expired CA certificates within the vmdir.