"Certificate chain of Compute Manager <FQDN> is invalid. Please check Issuer and Subject in the chain. (Error code: 90204)"
2024-06-24T19:45:24.327Z ERROR http-nio-127.0.0.1-7443-exec-2 VcPlugin 4732 SYSTEM [nsx@6876 comp="nsx-manager" errorCode="MP40219" level="ERROR" reqId="11111111-2222222-7e7e7e7e7" subcomp="cm-inventory" username="admin"] Certificate of Vc VMware.org is invalid. it might be caused by issuer not being same as subject of next certificate in certificate chain.
The certificate chain of the custom machine SSL certificate on the vCenter may be incomplete, or there could be an incorrect or missing entry within the new certificate.
For example, the Subject Alternative Name section of the custom machine SSL certificate will need to include the FQDN, short name, and IP address of the vCenter Server. If the IP address is not included in the Subject Alternative Name (SAN) section of the custom machine SSL certificate, NSX will not be able to validate the connection to the vCenter Server, resulting in this error message.
Another possibility is that the machine SSL certificate only uses the 'leaf' certificate and not the 'full certificate chain', which includes the intermediate CA(s) and root CA.
This is a condition that may occur in a VMware NSX environment.
Workaround
KB articles that may assist with this process:
After VMware vCenter Server certificate is replaced, compute manager connection is "Down" on NSX UI