Unused Expired NSX Certificates
search cancel

Unused Expired NSX Certificates

book

Article ID: 406369

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • Is there any impact to NSX Manager functionality if self signed cert are showing not in use?
  • Are those self signed certificate required?
  • If required how to renew the self signed cert which are not in use?

Environment

NSX 4.2.x

Cause

After replacing/renewing NSX certificates, either self-signed or CA-signed, there may be lingering expired certificates still present in the NSX UI.
CARR script does not delete unused certificates, this has to be performed manually.
 
Expired certificates that are unused can cause:

  • Unnecessary alarms, indicating that a certificate may need to be replaced
  • False report of which certificates are actually valid or have expired

Resolution

On the NSX UI, System > Certificates, if the "Used By" column shows zero, the certificate is not in use and can be safely deleted.

The following example outlines the procedure for removing unused certificates (both CA and self-signed):

  1. Log into the NSX UI with the admin credentials and ensure there is a recent backup of the NSX Managers by selecting System > Backup & Restore (please perform one prior to moving forward if a recent backup has not occurred). 
  2. To view the certificates while still on the System tab, select Certificates
  3. Verify that the certificate is expired and has zero in the Used By column.





    It is recommended to validate that the unused and expired certificates have equivalent new certificates showing as in use from a previous successful replacement.

  4. Select the certificate and click on the Actions drop down menu to select Delete Certificates:



  5. Refresh the NSX UI and confirm if the unused/expired certificate is still present.