Error: ESXi thumbprint mismatch after certificate rotation for vSphere Replication
search cancel

Error: ESXi thumbprint mismatch after certificate rotation for vSphere Replication

book

Article ID: 451622

calendar_today

Updated On:

Products

VMware Live Recovery

Issue/Introduction

  • This article addresses a connection failure between the vSphere Replication Management Server and the vSphere Replication Server.
  • This typically occurs after an ESXi host or vCenter Server certificate renewal where the thumbprint information is not synchronized.
  • vSphere Replication Management Server is unable to establish a connection to the vSphere Replication Server.
  • ESXi host reports SSL handshake failures.
  • "Broken pipe" errors observed in replication logs.

 

Environment

VMware vSphere Replication 9.x

Cause

A certificate renewal occurred on the ESXi host or vCenter Server, but the hbr-agent process on the ESXi host and the vSphere Replication appliance internal database (hbrsrv) did not synchronize the updated certificate thumbprint.

Resolution

 To synchronize the certificate thumbprints, follow these steps:

  1. Log in to the vSphere Client and select the target ESXi host.
  2. Navigate to Configure > System > Services.
  3. Locate hbrsrv and click Restart.
  4. Locate hbr-agent and click Restart.
  5. Verify that the virtual machine replication status returns to OK or Active.

Note: If the issue persists, reboot the vSphere Replication appliance to force a full synchronization.

Additional Information