Unable to replace Global-Manager and Local-Manager self-signed certificates with CA signed
search cancel

Unable to replace Global-Manager and Local-Manager self-signed certificates with CA signed

book

Article ID: 417307

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

NSX UI does not display CA signed certificates in the drop-down menu while replacing GLOBAL_MANAGER and LOCAL_MANAGER certificates:

Environment

VMware NSX

Cause

This is an expected behavior.
By default, the Global Manager uses self-signed certificates for communicating with internal components, registered Local Managers, and for authentication for NSX Manager UI or APIs.

Resolution

GLOBAL_MANAGER and LOCAL_MANAGER are client certificates used for communicating with other sites in Federation and by default use self-signed certificates.
https://techdocs.broadcom.com/us/en/vmware-cis/nsx/vmware-nsx/4-2/administration-guide/certificates/certificates-for-nsx-and-nsx-federation.html 
These can be replaced with another self-signed certificate via UI.