Certificate fails to delete on NSX Manager
search cancel

Certificate fails to delete on NSX Manager

book

Article ID: 413704

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • A certificate has been deleted through NSX UI.
  • The given certificate is grayed out, with a trashcan icon next to the certificate (indicating intent to delete).
  • Deletion of the certificate won't proceed. 
  • In NSX Manager logs, you will see logging similar to the logs below:
    /var/log/syslog:
    2025-10-08T14:55:00.546Z <nsx-manager> NSX 5134 SYSTEM [nsx@6876 comp="nsx-manager" level="INFO" subcomp="manager"] Attempting to delete certificate ########-####-####-####-########4383
    2025-10-08T14:55:09.063Z <nsx-manager> NSX 5134 POLICY [nsx@6876 comp="nsx-manager" errorCode="PM0" level="ERROR" subcomp="manager"] Created alarm Alarm [policyPath=/infra/realized-state/enforcement-points/default/certificates/########-####-####-####-########e02e/alarms/########-####-####-####-########9343, message=One or more relationships exist for object with id Certificate/########-####-####-####-########4383.,errorId=PROVIDER_INVOCATION_FAILURE, path=null, apiError=error_code=3022, module_name=internal-framework, error_message='One or more relationships exist for object with id Certificate/########-####-####-####-########4383.', sourceSiteId=null].

Environment

VMware NSX

Cause

The certificate is still in use, likely on a Load Balancer server configured in NSX.

Resolution

  • The certificate is still being consumed, usually by a Load Balancer server.
  • You can search for the certificate UUID in NSX Manager's elastic search.
  • Once the certificate is replaced (or detached) on the entity/entities consuming it, it's deletion will complete.