'Certificate expired' alarm occurred in NSX UI but not seen in SDDC Manager
search cancel

'Certificate expired' alarm occurred in NSX UI but not seen in SDDC Manager

book

Article ID: 389616

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • NSX Manager deployed by VMware Cloud Foundation.
  • NSX Manager UI shows alarm of 'Certificate expired'.
  • However the alarm does not happen in SDDC Manager UI.

 

Environment

VMware NSX
VMware Cloud Foundation

Cause

SDDC Manager automatically rotates NSX Manager API certificates. But those old certificates which have been rotated remain in NSX Manager trust store that cause alarms happening. 

Resolution

  • If 'Used by' field is empty the certificate is not used by any entity and can be safely deleted from NSX UI - System - Certificates.