A security audit shows "X.509 Server Certificate is Invalid/Expired" message linked it to Spotlight Diagnostic Server. If changed the port used for the listener in the webservice.xml file located at ...\Diagnostic Server\Agent\conf\Service the "expired certificate" is tied to that port 443 in the webservice.xml
Alert in Spotlight:
Cannot connect to VMware server 'NNNN' : The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel.: The remote certificate is invalid according to the validation procedure
Firstly, restart the Diagnostic Server service to check if the error re-occurred. If that doesn't help then restart the Diagnostic Server host/machine.
If restart DS service or DS host doesn’t help, please try to do the following steps:
1. You can either obtain a new certificate of 1024 bits or ...
2. Uninstall KB2661254 (http://support.microsoft.com/kb/2661254).
3. Add a registry key to allow keys of less than 1024 bits. (See the above KB article for details)
Microsoft has released a Microsoft security advisory for IT professionals. This advisory announces that the use of RSA certificates that have keys that are less than 1024 bits long will be blocked. For more information on this you can visit the following web site:
http://www.informationweek.com/security/attacks/microsoft-warns-of-looming-digital-certi/240006954