Skip to main content
Solved

PKi Cert has expired on Vcenter Server and Veeam can't connect to backup VMs.


Hi, Our PKI cert has expired on our VCS server, and as a result the backups of the VMs are failing as Veeam can’t connect to the VCS.  Its going to take us a few days to get another cert generated and installed on the VCS - but is there any workaround we can do in the meantime to get the Veeam Backup and Replication software to backup our VMs?  I’m assuming not really - as that’s the point of certificates!

Any suggestions most welcome.

Thanks...

 

Best answer by Chris.Childerhose

If I remember right the suggestions above might work but I think you might need to wait until you replace the certificate.  I am pretty sure this happened in my lab and Veeam didn't work until I updated the certificate.

View original
Did this topic help you find an answer to your question?

8 comments

MicoolPaul
Forum|alt.badge.img+23
  • 2358 comments
  • November 30, 2023

Hi,

 

You can try going to inventory > vCenter and editing your impacted vCenter to see if you can get Veeam to proceed through the error, but as you say, it’s doing its job. I’d say just quickly generate a self-signed in vCenter and get Veeam to trust that until you’ve got your new public one generated would be the fastest workaround. Otherwise it’ll be over to Veeam support to see if they’ve got any registry keys to ignore expiration.


coolsport00
Forum|alt.badge.img+20
  • Veeam Legend
  • 4109 comments
  • November 30, 2023

Try and go to the Managed Servers, rt-click on your vCenter, go into the Properties and go through the process/wizard again. When you're prompted with a cert msg, click Continue. See if that works. 


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8402 comments
  • Answer
  • November 30, 2023

If I remember right the suggestions above might work but I think you might need to wait until you replace the certificate.  I am pretty sure this happened in my lab and Veeam didn't work until I updated the certificate.


  • Author
  • Not a newbie anymore
  • 5 comments
  • November 30, 2023

We did go through the procedure suggested - but unsurprisingly it didn’t like the expired certificate and wouldn’t complete the wizard.  Ok- thanks anyway, I’ll just wait for the new cert.


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8402 comments
  • November 30, 2023
phil123456789 wrote:

We did go through the procedure suggested - but unsurprisingly it didn’t like the expired certificate and wouldn’t complete the wizard.  Ok- thanks anyway, I’ll just wait for the new cert.

That is what I thought, and you need the new SSL.  Best of luck once you get it renewed but backups should start working again.


dloseke
Forum|alt.badge.img+7
  • On the path to Greatness
  • 1447 comments
  • November 30, 2023

As Michael noted, I’d probably just generate a new self-signed cert.  It’s pretty easy really.  And if you want a publicly signed cert, you can always add that later on, but a self-signed would at least get things running again.

Link below for info on generating new certs in the vCenter Certificate Manager.

https://kb.vmware.com/s/article/2112283

 


  • Author
  • Not a newbie anymore
  • 5 comments
  • January 22, 2024

Hi,   Just to resolve this one - we did resolve it in the end, but had to wait until we got a new PKI certificate for it.  Once we’d one that, Veeam started to try and backup VMs.  From memory, we had an issue where a load of the VM backups then failed due to locked .vib (?) files , but once we migrated them between hosts, they all backed up again, and all was well with the world.  


Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8402 comments
  • January 22, 2024
phil123456789 wrote:

Hi,   Just to resolve this one - we did resolve it in the end, but had to wait until we got a new PKI certificate for it.  Once we’d one that, Veeam started to try and backup VMs.  From memory, we had an issue where a load of the VM backups then failed due to locked .vib (?) files , but once we migrated them between hosts, they all backed up again, and all was well with the world.  

Great to hear you were able to resolve the issue and post back here. 👍🏼


Comment