"SSL handshake failed" and "Broken pipe" errors quite frequently. WARNING: Hbr: 788: Failed to receive from 127.0.0.1 (groupID=GID-######-####-####-####-###########): Broken pipeWARNING: Hbr: 788: Failed to receive from 127.0.0.1 (groupID=GID-######-####-####-####-###########): Connection reset by peerNo connection to VR Server for virtual machine on host in cluster : Unknown
The source ESXi host's /var/run/log/hbr-agent.log records SSL handshake rejections when connecting to the target ESXi host on port 32032.
hbr-agent-bin[2104599]: [0x00000065ff149700] error: [Proxy [Group: GID-######-####-####-####-###########] -> [ESXi_Host_IP:32032]] SSL handshake failed: certificate verify failed (SSL routines)
Target VR Appliance (hbrsrv.log) shows the target server blocking the incoming stream due to an untrusted peer.
error hbrsrv[716413] [Originator@6876 sub=Broker groupID=GID-######-####-####-####-########### opID=###] Lookup request for group 'GID-######-####-####-####-###########' on SSL could not verify peer. Rejecting.
error hbrsrv[716413] [Originator@6876 sub=Main groupID=GID-######-####-####-####-########### opID=###] Thumbprint and certificate is not allowed to send replication data
error hbrsrv[716413] [Originator@6876 sub=Main groupID= opID=###] Converting error to wire failureGID-######-####-####-####-###########
vSphere Live Site Recovery (vLSR) 9.0.2
VMware ESXi 8.0 U3
VMware vCenter Server 8.0 U3
An SSL certificate trust mismatch occurred between the source ESXi host and target ESXi host/VR appliance during the TLS handshake on port 32032.
The vSphere Replication Management Server (hms) failed to automatically synchronize the updated certificate thumbprint from vCenter to the source host after a possible target host certificate rotation.
Reboot the vSphere Replication (VR) appliances to clear the stale state and force service initialization.
Alternatively, SSH into the VR Appliance and restart the management and replication services directly via CLI.systemctl restart hmssystemctl restart hbrsrv