The Backup Radar integration with Veeam Service Provider Console (VSPC) uses HTTPS to connect to the VSPC REST API. If the VSPC server presents an expired, mismatched, incomplete, or untrusted SSL certificate, Backup Radar might not be able to connect.
Certificate issues can appear after a certificate renewal, even when the VSPC services are running and the API key is valid. Use the checks below to confirm that the VSPC endpoint presents a certificate that Backup Radar can validate.
Note: This article includes general checks for a third-party VSPC server. VSPC screens and server-management steps can change. For product-specific instructions, see Veeam’s documentation or contact the person who manages your VSPC server.
Check the VSPC hostname and port
Confirm that the Availability Console Link in Backup Radar:
Uses
https://.Uses the exact hostname covered by the certificate.
Uses the correct VSPC port, which is commonly
1280.Does not use an IP address unless the certificate explicitly includes that IP address.
The hostname in the Backup Radar integration must match a name in the certificate’s Subject Alternative Name (SAN) field. A certificate issued to a different hostname can fail validation even when the certificate has not expired.
For more details about the integration fields, see Integrating with Veeam Service Provider Console (VSPC) API.
Verify the certificate’s validity
Ask the person who manages the VSPC server to verify that the certificate:
Has not expired.
Is not marked as not yet valid.
Is issued for the hostname used in Backup Radar.
Includes a private key on the VSPC server.
Is the certificate that the VSPC listener uses on the configured port.
A certificate can appear valid in the server’s certificate store but still fail if VSPC presents a different certificate to external connections.
Verify the certificate binding
After a certificate renewal, confirm that the VSPC listener uses the renewed certificate rather than the previous certificate.
The server administrator must:
Compare the certificate bound to the VSPC listener with the renewed certificate, using the certificate thumbprint or another unique identifier.
Confirm that the binding applies to the hostname and port used by Backup Radar.
Rebind the certificate or restart the VSPC listener after correcting the binding.
Test the endpoint again from an external network.
Verify the complete certificate chain
The VSPC endpoint must present enough of the certificate chain for the connecting service to build a trusted path. The server normally presents:
The server certificate for the VSPC hostname.
Any required intermediate certificates.
The connecting service must have access to the trusted root certificate. The server does not usually need to send the root certificate itself.
Ask the server administrator to confirm that:
The intermediate certificates are installed correctly.
The endpoint presents the intermediate certificates externally.
The chain builds to a trusted root without errors.
The endpoint does not report
PartialChain,unable to get local issuer certificate, or a similar chain-validation error.
A certificate can pass a local chain check while the externally presented chain is incomplete. A result from a browser or third-party SSL checker also does not guarantee that the Backup Radar connection environment trusts the same certificate chain.
Test the endpoint externally
Test the VSPC URL from a network outside the VSPC server’s local network. Use the same hostname and port configured in Backup Radar.
Confirm that:
The browser does not show a certificate warning.
The endpoint responds over HTTPS.
The certificate details show the expected hostname, issuer, and expiration date.
The test is performed from a source network allowed by the VSPC firewall, proxy, or WAF.
If your VSPC API supports it, you can also test an API endpoint such as the following without including an API key in a support request:
GET https://<your-vspc-hostname>:1280/api/v3/An HTTP response confirms that the endpoint is reachable, but it does not by itself prove that the API key has the required permissions. A 401 or 403 response after the TLS connection succeeds can indicate an authentication or authorization issue instead of a certificate issue.
Check the error message
The error message can help identify which check to perform first:
Error or symptom | What to check |
|---|---|
| The issuer, root trust, and complete certificate chain. |
| Missing or incorrectly presented intermediate certificates. |
| Whether the chain builds to a trusted root. |
| Certificate validation, TLS negotiation, firewall, proxy, and WAF settings. |
The integration fails immediately after certificate renewal | The renewed certificate binding, externally presented chain, and any certificate trust or caching behavior. |
| Test the certificate separately before treating the issue as an API-key problem. |
Check network access separately
A valid certificate does not allow the connection through a firewall or proxy. If the VSPC server restricts inbound traffic, allow the current Backup Radar IP addresses for your hosting region and permit TCP traffic to the VSPC port.
For the current addresses, see IP Address Allow Lists. Use the current list for your Backup Radar hosting region rather than the legacy addresses.
Retry the integration
After correcting the certificate or network configuration:
Rebind the certificate or restart the VSPC listener if required by the server configuration.
Test the VSPC endpoint externally again.
Retry the existing Backup Radar integration.
If the integration still fails, create a support ticket and include the error message, VSPC hostname without credentials, certificate issuer, certificate expiration date, VSPC version, approximate retest time, and relevant redacted firewall or proxy logs.
Do not include an API key or other credentials in a support ticket.
| ✉️ Any questions? Reach out to our friendly, neighborhood support team by submitting a support ticket. |
| 🎙️ Interested in attending a live Q&A session with our Product Adoption team? Sign up to attend Backup Radar Office Hours and get real-time answers to your questions. |