The following errors occur after replacing or rotating the vCenter Server Machine SSL certificate:
com.vmware.vim.vmomi.core.exception.CertificateValidationException. Server certificate chain is not trusted and thumbprint verification is not configured.The remote host certificate has these problems: * unable to get local issuer certificatesUnable to retrieve pairs from extension server at https://####:8043. Unable to login to 'HBR Management Server at https://####:8043'/opt/vmware/support/logs/dr-client/dr.log: javax.net.ssl.SSLException: Certificate thumbprint mismatch."Unable to retrieve pairs from extension server at https://hostname:8043. Unable to login to 'HBR Management Server at https://hostname:8043'"
a
(from /opt/vmware/support/logs/dr-client/dr.log) in vSphere Replication appliance (or from Vmware Live Site Recovery):
2026-04-21 09:48:56, 622 [srm-reactive-thread-24966] WARN com. vmware.srm.client. infrastructure.http. BaseAsyncController aa88f6ec-9128-4cb1-a703-a35c876ee9 - Request for path 'webssologin' failed.
com.vmware.srm.client.topology.impl.vmomi.TokenProvider$AuthenticationTokenNotAvailable: No authentication token available for SSO Server at 'https://<vcenter-FQDN>/sts/STSService/vsphere.local
at com. vmware. srm. client. topology. impl.core.mxn. nodes. TokenProvider Impl. lambda$getToken$1 (TokenProviderImpl. java:56)at com. vmware. dr.ui. tools. reactive. impl. Promise Impl$ApplyCompletion. complete (PromiseImpl. java: 239)at com. vmware.dr.ui. tools. reactive. impl. PromiseImpl$Result. complete (PromiseImpl. java: 41)
Suppressed: com. vmware. vim. vmomi. client. exception. SslException: Unable to connect to SSO Management Server at https://<vcenter-FQDN>/o-adminserver/sdk/vsphere. local. Reason: javax.net.ssl. SSLException: Certificate thumbprint mismatch.at com. vmware. vim. vmomi. client. common. impl. ResponseImpl. setError (ResponseImpl. java: 265)
Caused by: javax.net.ssl. SSLException: Certificate thumbprint mismatch.at com. vmware. srm.client.topology. impl. vmomi. ssl. DynamicVerifier. onSuccess (DynamicVerifier. java: 80)at com. vmware. vim. vmomi. client.http. impl. HttpConfigurationCompilerBase$1.onSuccess (HttpConfigurationCompilerBase. java: 224)
Follow these steps to reconfigure the appliances and restore the trust relationship:
https://<VR-Appliance-IP>:5480).https://<SRM-Appliance-IP>:5480).To speak with a customer representative or a Support Engineer, see . Scroll to the bottom of the page and click on your respective region.