Site-Manager synchronization fails with certificate error in a Federation setup when the GM is 3.1.x and one LM is upgraded to 3.2.x
search cancel

Site-Manager synchronization fails with certificate error in a Federation setup when the GM is 3.1.x and one LM is upgraded to 3.2.x

book

Article ID: 319041

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • Site-Manager synchronization fails with a certificate error in a Federation setup when the Global Manager and Local Manager are on 2 different NSX-T versions (Ex: GM is 3.1.x and LM is upgraded to 3.2.x) 
  • The following error is displayed for one or more LMs in the Global Manager UI when user navigates to System > System Overview:

    "I/O error on GET request for "https://.........." . . . .. PKIX path building failed: ………….. Unable to find certificate chain"

  • Logging seen in /var/log/gmanager/gmanager.log on the Global Manager:

    202x-xx-xxTxx:xx:xx.xxxZ  INFO http-nio-127.0.0.1-64440-exec-208 RemoteSiteStatusFacadeImpl 5797 - [nsx@6876 comp="global-manager" level="INFO" reqId="xxxxxxxx-dxxx-4xxx-b2xx-51xxxxxxxx" subcomp="global-manager" username="admin"] Was not able to get data from remote site xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxx. Error I/O error on GET request for "https://xx.xx.xx.xx/api/v1/ui-controller/clusters-overall-status": sun.security.validator.ValidatorException: PKIX path building failed: java.security.cert.CertPathBuilderException: Unable to find certificate chain.; nested exception is javax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException: PKIX path building failed: java.security.cert.CertPathBuilderException: Unable to find certificate chain..

Environment

  • VMware NSX
  • Federated NSX installation where two different NSX versions are in use and one is below 3.2.

Cause

The site_type property is an unrecognized type in 3.1.x releases of NSX and was introduced in 3.2.x. When the Federated setup is partially upgraded, i.e. when only one or more LMs are upgraded, onboarding a new LM will fail.

Resolution

Complete the Global Manager upgrade to bring Local Manager and Global Manager to the same versions.

Additional Information

Impact/Risks:
  • Unable to onboard new sites to GM.
  • Inconsistencies in GM and LM configs