Once the renewed CA signed certs are exported properly, you can follow the below steps to replace the corresponding services:
- With admin privileges, log in to NSX Manager.
- Navigate to System > Certificates.
- To replace a certificate, perform the following steps:
- Select the certificates you want to replace, and click Actions > Replace Certificates.
- In the Replace Certificates dialog box, click on the three dots drop down menu and select "Import Certificates"
- Supply the information for the imported cert then import and save
- NSX manager will finalize the replacement, you may see brief UI refresh when this is happening
- This process usually does not affect NSX functionalities and should not have any impact on dataplane activities as well
- One CA signed cert can only be used for one service, if you are attempting to use the same cert again, the NSX manager will show an error that the cert has already being used.
- Make sure multiple CA signed certs are generated for each service you are trying to replace