"Unable to validate/update plugin server thumbprint in vCenter Extension" in DSM 9.x on vCenter certificate replacement
search cancel

"Unable to validate/update plugin server thumbprint in vCenter Extension" in DSM 9.x on vCenter certificate replacement

book

Article ID: 454751

calendar_today

Updated On:

Products

VMware Data Services Manager

Issue/Introduction

  • The vCenter machine certificate is replaced.

  • Subsequently, Data Services Manager reports the Global Alert:

    "Unable to validate/update plugin server thumbprint in vCenter Extension: Post \"https://<DSM appliance FQDN>/sdk\": tls: failed to verify certificate: x509: certificate signed by unknown authority"

  • Manually updating the target vCenter thumbprint does not resolve the issue (i.e. Under DSM UI Settings tab, edit the target vCenter and update the thumbprint with current thumbprint of the vCenter and save.)  

Environment

VMware Data Services Manager 9.x

Cause

  • In addition to changing the vCenter machine cert, the CA root/intermediate certs which sign it were also changed. 

  • /var/log/tdm/provider/provider.log.log reports:

ERROR dsm-provider 1 [dsm@4413 threadName="http-nio-8084-exec-2" class="oviderVCenterClientServiceImpl"] Error retrieving vCenter version
java.util.concurrent.ExecutionException: com.vmware.vim.vmomi.client.exception.SslException: com.vmware.vim.vmomi.core.exception.CertificateValidationException: Server certificate chain is not trusted and thumbprint verification is not configured

Resolution

Add the new CA root/intermediate certs to the DSM trusted root certificates.

See Configure or Update Trusted Root Certificates for VMware Data Services Manager