openssl check: openssl s_client -connect <VC_IP>:443 -showcerts
... run in the root shell of and NSX Manager node shows: "Verify return code: 20 (unable to get local issuer certificate)"
VMware NSX-T Data Center
VMware vCenter Server
NSX Manager is unable to trust the Machine SSL certificate from the vCenter Server because of a problem with certificates such as an expired STS certificate, a mismatched SSL trust anchor, or both on the vCenter Server.
Resolve certificate issues with the vCenter Server and then retry the Compute Manager edit again. Refer to Resolving SSL Trust Mismatch Errors in VCSA Due to Expired Certificates and Misconfigured Chain Elements
The vCert Tool in vCert - Scripted vCenter Expired Certificate Replacement may also be used to identify and resolve those kinds of issues.
A similar issue may occur if the Machine SSL Certificate on the vCenter Server does not include a complete chain as shown at NSX Compute Manager 'Connection Status' Down
Additional helpful information at vCenter Server certificate validation error for external solutions in environments with vCenter Server 7.0