Error will show in the NSX-UI > Security > IDS/IPS Malware Prevention > Signature Management > Bundle Version
NSX versions 4.x
This is caused by NSX Manager not being able import the required CA Certificate for TLS inspection.
In the /var/log/proton/nsxapi.log you will see errors related to IDS.
2025-01-01T00:00:00.000Z ERROR IDS_AUTO_DOWNLOAD_TASK-0 IdsSignatureUtils 76868 POLICY [nsx@6876 comp="nsx-manager" errorCode="PM523931" level="ERROR" subcomp="manager"] IDS - Got Error while downloading Sign
ature Bundle from NSX Intel Cloud
org.springframework.web.client.ResourceAccessException: I/O error on POST request for "https://api.prod.nsxti.vmware.com/2.0/auth/register": PKIX path building failed: java.security.cert.CertPathBuilderExcept
ion: Unable to find certificate chain.; nested exception is javax.net.ssl.SSLHandshakeException: PKIX path building failed: java.security.cert.CertPathBuilderException: Unable to find certificate chain.
-
With Cause;
Caused by: sun.security.validator.ValidatorException: PKIX path building failed: java.security.cert.CertPathBuilderException: Unable to find certificate chain.
Caused by: java.security.cert.CertPathBuilderException: Unable to find certificate chain.
This is a known issue affecting NSX
As a workaround you can download the bundle offline by using the documentation link below for "Downloading Signatures Manually." Another option would be to bypass the Transparent Proxy or have an exception for this signature download process.
vDefend IDS Documentation =
https://techdocs.broadcom.com/us/en/vmware-security-load-balancing/vdefend/vdefend-atp/4-2/nsx-ids-ips-and-nsx-malware-prevention/nsx-ids-ips-and-nsx-malware-prevention/getting-started-with-nsx-ids-ips-and-nsx-malware-prevention/configuring-nsx-ids-ips-and-nsx-malware-prevention-settings.html
Downloading Signatures Manually = https://techdocs.broadcom.com/us/en/vmware-security-load-balancing/vdefend/vdefend-atp/4-2/nsx-ids-ips-and-nsx-malware-prevention/nsx-ids-ips-and-nsx-malware-prevention/offline-downloading-and-uploading-nsx-intrusion-detection-signatures.html
Create a Broadcom NSX support case = https://knowledge.broadcom.com/external/article/142884/creating-and-managing-broadcom-support-c.html