Note: If this KB does not match your issue, there is a similar issue "OVF certificate validation failed. Error: [VALIDATION_ERROR: CERTIFICATE_EXPIRED; ]" error for NSX Manager deployment or Deploying a service vm ( SVM ) in NSX fails due to "Error creating agency for deployment unit ########-####-####-####-############. OVF certificate validation failed".
VMware NSX
The primary cause of the deployment failure has been an expired OVF certificate used by the existing NSX Manager nodes for deploying new appliances. Specifically, the Tomcat certificates (Service Type = API) and/or mp-cluster certificates (Service Type = MGMT_CLUSTER) have expired on the operational NSX Manager nodes.
Once these certificates have expired, NSX Manager’s ability to trigger deployment workflows for new Managers or Edges has been affected, resulting in the observed OVF certificate validation failure. This has been identified as expected product behavior.
Please refer to the KB to renew the certificates on the NSX manager:
Using Certificate Analyzer, Results and Recovery (CARR) Script to fix certificate related issues in NSX
Renew or replace the self-signed SSL certificates assigned to various components of NSX version 4.2 and later through the GUI interface Only.