yyyy-mm-ddThh:mm:ss.Z warning vmware-vum-server[xxxxx] [Originator@6876 sub=IO.Connection] Failed to SSL handshake; SSL(<io_obj p:0x0000000000000000, h:49, <TCP '127.0.0.1 : 40834'>, <TCP '127.0.0.1 : 443'>>), e: ###########(certificate verify failed (SSL ROUTINES)), duration: 20msecyyyy-mm-ddThh:mm:ss.Z warning vmware-vum-server[xxxxx] [Originator@6876 sub=HttpConnectionPool-000000] Failed to get pooled connection; <cs p:0000000000000000, TCP:<VC_FQDN>:443>>, SSL(<io_obj p:0x0000000000000000, h:49, <TCP '127.0.0.1 : 40834'>, <TCP '127.0.0.1 : 443'>>), duration: 54msec, N7Vmacore3Ssl18SSLVerifyExceptionE(SSL Exception: Verification parameters:--> PeerThumbprint: ##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:## <==== This Thumbprint should match the Custom Machine SSL certificate--> ExpectedThumbprint: ##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:##:## <==== This Thumbprint will be the old vCenter Machine SSL certificate--> ExpectedPeerName: <VC_FQDN>VMware vCenter Server 8.x
Updating the Machine SSL certificate via the vSphere Client restarts only specific services.
The Lifecycle manager services are excluded from this automatic restart, preventing the certificate update from being reflected for this service.
Restart the VMware Update Manger Service to reload the certificate in the service:
service-control --restart vmware-updatemgrOnce the service is restarted, reloading the UI will populate the Baselines and Images.