NSX Manager Node certificate CN or SANs are not valid for <manager-IP>
Replace the NSX Manager Node certificate with a valid certificate where the hostname matches the CN name or is specified in the SAN field. Please refer the Certificates section in NSX Admin Guide for more details.
Additional Symptoms:
|
VCF 9
VCF 9.0 SDDC import has incorrect validation for wildcard certificates, causing the import to fail.
If the symptoms persist after performing the workaround, the reverse DNS record may be pointing to a server name other than the NSX Manager VIP node.
This issue is resolved in VCF 9.0.1 SDDC manager, available at Broadcom downloads.
Whereby wildcard certificates used on NSX managers are imported correctly.
If you are having difficulty finding and downloading software, please review the Download Broadcom products and software KB.
Workaround:
Replace the NSX manager API and cluster certificates with certificates that have the hostname as the CN, or that include the hostname in the SAN field and do not use a wildcard.
There is a script in the KB below that can be used to generate CA certificates from the vCenter VMCA:
Once the certificates are replaced with certificates that conform to the SDDC manager requirements, try the import option again.
If the symptoms persist after applying the workaround, ensure that the reverse DNS record points to the FQDN of the NSX Manager VIP node.
Please review the following KB for details on supported SDDC certificates:
Replacing SDDC manager certificates with custom certs failed with " Could not resolve the hostname"