Upgrade to NSX for vSphere 6.3.5 may fail in an environment using CA certificates
book
Article ID: 336527
calendar_today
Updated On:
Products
VMware NSX
Issue/Introduction
Symptoms: In an environment using CA certificates on the NSX Manager, upgrade of the Manager to 6.3.5 may fail with these symptoms:
The NSX Manager appliance User Interface (UI) may fail to load or continue to show a spinning wheel indicating the upgrade in progress. However, when the web page is refreshed, it fails to load.
On the vSphere Web Client under Network & Security, no NSX Manager is present.
In the /var/log/appmgmt-wrapper.log file, you see entries similar to:
INFO | jvm 1 | 2017/11/20 13:20:49 | 20-Nov-2017 13:20:49.046 SEVERE [WrapperStartStopAppMain] org.apache.coyote.AbstractProtocol.init Failed to initialize end point associated with ProtocolHandler ["https-jsse-nio-443"] INFO | jvm 1 | 2017/11/20 13:20:49 | java.lang.IllegalArgumentException: java.security.KeyStoreException: Cannot store non-PrivateKeys
Note: The preceding log excerpts are only examples. Date, time, and environmental variables may vary depending on your environment.
Environment
VMware NSX for vSphere 6.3.x
Cause
This issue occurs only in environments which have a CA certificate configured on the NSX Manager.
Resolution
This issue is resolved in VMware NSX for vSphere 6.3.6.
Workaround: To work around this issue if you do not want to upgrade, file a support request with VMware Technical Support and note this Knowledge Base article ID (51960) in the Problem Description.