VMware Cloud Director fails to connect to NSX-T post certificate change on NSX-T manager
search cancel

VMware Cloud Director fails to connect to NSX-T post certificate change on NSX-T manager

book

Article ID: 416553

calendar_today

Updated On:

Products

VMware Cloud Director VMware NSX

Issue/Introduction

  • Connecting VMware Cloud Director(vcd) to NSX-T asks to trust the certificate of NSX-T. When "Trust" is selected, below error pops up and cannot proceed:

    The certificate is already trusted.

  • There are three NSX-T manager appliances forming a cluster and VMware Cloud Director is connecting to NSX-T VIP.
  • The certificate of NSX-T manager has been renewed lately.
  • Notice the Subject Alternative Name(SAN) in the certificate is the FQDN name of one NSX-T manager appliance instead of the FQDN of NSX-T VIP.

Environment

VMware Cloud Director 10.x
VMware NSX-T Data Center

Cause

The SAN in NSX-T mp-cluster certificate is the FQDN of one NSX-T manager appliance but not FQDN of NSX-T VIP causing failure during certificate verification when connecting to NSX-T VIP.

Resolution

Re-generate NSX-T mp-cluster certificate with FQDN of NSX-T VIP.

Additional Information

For more information on certificate replacement for NSX-T, please refer to: Replace Certificates.