/var/log/proton/nsxapi.log:INFO RepoSyncThread-1746706374224 RepoSyncFileHelper 5414 SYSTEM [nsx@6876 comp="nsx-manager" level="INFO" subcomp="manager"] Command to get server info for https://####:443/repository/<nsx version>/Manager/dry-run/dry_run.py returned result CommandResultImpl [commandName=null, pid=0, status=FAILED, errorCode=51, errorMessage=curl_wrapper: (51) SSL: no alternative certificate subject name matches target host name '####'
Note: The preceding log excerpts are only examples. Date, time, and environmental variables may vary depending on your environment.
VMware NSX 4.x
There is a single certificate applied to all 3 NSX Manager API services and the VIP.
The certificate has its CN (Common Name) matching one NSX Manager or the VIP FQDN, and not a wildcard.
Not all 3 NSX Managers and VIP FQDNs are included in the SAN (Subject Alternative Name) field.
When an NSX Manager tries to connect to another NSX Manager, which is not part of the certificate SAN entry, it will fail, as the certificate is not valid for that node.
To resolve this issue:
NSX Administration guide: Certificates
There are other issues with similar symptoms that should be reviewed and ruled out: