Below message we see in Task error details,
Cause: VO error on GET request for "https://nsxmanagerclusterfqdn/api/v1/node/users": PKIX path validation faled:
ava security cert.CertPathValidatorxception: validity check failed; nested exception is
avax.net ssl.SSLHandshakeException PKK path valdation faled:
ava securiky cert CertPathValdatorException: validty check falled
VCF 5.1.x
VCF 5.2.x
NSXT Managers certificates are expired.
It can be confirmed on the certificates tab under Domain view in SDDC UI.
We can also confirm by viewing certificate from browser for the NSXT Manager URL.
Certificates from NSXT Manager UI needs to be replaced to self signed.
Once the self signed certs are install and are ACTIVE in SDDC we can replace the CA certificates again from SDDC UI as specified in below doc,