NSX Manager certificate replacement fails through UI or Batch API replacement.
The following error is observed when attempting to replace the certificate:
A certificate batch replace operation cannot be started at this time because conflicting operations are running: TRANSPORT_NODE_ONBOARDING_IN_PROGRESS. Try again later. (Error code: 2190)Error screenshot as seen from NSX UI > System > Certificates > Select the certificates you want to replace > Actions > Replace Certificates :
VMware NSX
An alarm is triggered during certificate replacement if any Transport Node is in a non-healthy state, such as HOST_DISCONNECTED or INSTALL_FAILED.
This is a condition that may occur in a VMware NSX environment.
It is recommended to:
As an alternative, you can use the CARR script to replace the certificates. This is recommended if the above procedures aren't working or if you have additional certificates that need to be replaced because they are expired or are expiring soon. Please reference KB 369034 - Using Certificate Analyzer, Results, and Recovery (CARR) script to fix certificate related issues in NSX.