Unable to upgrade NSX on host after upgrading ESXi to 8.0u3
search cancel

Unable to upgrade NSX on host after upgrading ESXi to 8.0u3

book

Article ID: 412206

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

Error present for failed attempt to prepare ESXi for NSX.

“Failed to install software on host. NSX Manager FDQN.nsxmanager.com has invalid API certificate. Error: (51) SSL: no alternative certificate subject name matches target host name 'FDQN.nsxmanager.com'”

Environment

VMware NSX

Cause

  • The NSX Manager’s certificate subject and SAN fields to not contain it's own FDQN.
  • The FQDN used in the request (FDQN.nsxmanager.com) is not listed in the certificate’s CN (Common Name) or SAN (Subject Alternative Name) fields.
  • ESXi is enforcing SSL hostname validation, so the handshake fails.

Resolution

Regenerate certificate with correct field data (including the correct FQDN in the CN or SAN fields) for the NSX Manager in question.