Upgrade to NSX for vSphere 6.3.5 may fail in an environment using CA certificates
search cancel

Upgrade to NSX for vSphere 6.3.5 may fail in an environment using CA certificates

book

Article ID: 336527

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

Symptoms:
In an environment using CA certificates on the NSX Manager, upgrade of the Manager to 6.3.5 may fail with these symptoms:
  • The NSX Manager appliance User Interface (UI) may fail to load or continue to show a spinning wheel indicating the upgrade in progress. However, when the web page is refreshed, it fails to load.
  • On the vSphere Web Client under Network & Security, no NSX Manager is present.
  • In the /var/log/appmgmt-wrapper.log file, you see entries similar to:

    INFO | jvm 1 | 2017/11/20 13:20:49 | 20-Nov-2017 13:20:49.046 SEVERE [WrapperStartStopAppMain] org.apache.coyote.AbstractProtocol.init Failed to initialize end point associated with ProtocolHandler ["https-jsse-nio-443"]
    INFO | jvm 1 | 2017/11/20 13:20:49 | java.lang.IllegalArgumentException: java.security.KeyStoreException: Cannot store non-PrivateKeys


    Note: The preceding log excerpts are only examples. Date, time, and environmental variables may vary depending on your environment.


Environment

VMware NSX for vSphere 6.3.x

Cause

This issue occurs only in environments which have a CA certificate configured on the NSX Manager.

Resolution

This issue is resolved in VMware NSX for vSphere 6.3.6.

Workaround:
To work around this issue if you do not want to upgrade, file a support request with VMware Technical Support and note this Knowledge Base article ID (51960) in the Problem Description.