Alarm For Transport Node Certificate Expiration Approaching
search cancel

Alarm For Transport Node Certificate Expiration Approaching

book

Article ID: 345823

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

Title: Alarm for transport_node_certificate_expiration_approaching
Event ID: transport_node_certificate_expiration_approaching
Alarm Description

  • Purpose: Notify User that Transport Node Certificate expiration is approaching in 30 days or less.

  • Impact: Transport Node can disconnect from Managers and not connect back again after the certificate expiry.

  • Cause: Transport Node certificate expiration is approaching in 30 days or less.  

    Warning: This alarm must be addressed as soon as possible. Once the TN certificate expires, there is a grace period of 24 hours after which all impacted Edges and Hosts will be disconnected from NSX.
  • Validate the expiry date of the certificate on the Host or Edge by running this command as root user:
    openssl x509 -enddate -noout -in /etc/vmware/nsx/host-cert.pem.

Environment

VMware NSX

Cause

  • NSX 4.1.x and 4.2.0, Edge and Host Transport Nodes are incorrectly instantiated using a certificate with validity period of 825 days.
  • NSX-T 3.x and NSX 4.2.1 and higher create Transport Nodes using a certificate with validity period of 10 years.
  • By design the Transport Node certificate used at create time is not replaced on upgrade.
  • As a result any Edge that may have been deployed or any Hosts prepared or re-prepared on these impacted versions will have this shorter validity period certificate.

Resolution

Follow the appropriate resolution step:

1) Transport Node has a certificate that has not yet expired:

or

2) This "About to Expire" alarm has been ignored and the Transport Node certificate has expired and TN is in a disconnected state in NSX: