NSX Upgrade Pre-check Failure
search cancel

NSX Upgrade Pre-check Failure

book

Article ID: 419952

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • Running Upgrade prechecks and it does not sync to the NSX managers
  • You see the following error in the UI

    Unable to connect to File /repository/4.2.2.2.0.../Manager/data-migration/cmdlets-4.2.2.0... on source ##.##.##.## Please verify that file exists on source and install-upgrade service is up.
  • On the nodes that are NOT the upgrade coordinator you may see the following in /var/log/proton/nsxapi.log

    2025-11-17T15:44:10.860Z  INFO RepoSyncThread-1763393868114 RepoSyncFileHelper 2533507 SYSTEM [nsx@6876 comp="nsx-manager" level="INFO" subcomp="manager"] Command to get server info for https://##.##.##.##:443/repository/4.1.1.0.0.22224312/HostComponents/linux64-sles12sp5-baremetal-server/upgrade.sh returned result CommandResultImpl [commandName=null, pid=899098, status=FAILED, errorCode=60, errorMessage=curl_wrapper: (60) certificate has expired

Environment

VMware NSX  4.1.1.0.0

Cause

The upgrade coordinator has Expired API Certificates.

Resolution

If the expired API certificates are self-signed then use the CARR script to replace them. Refer to Using Certificate Analyzer, Results and Recovery (CARR) Script to fix certificate related issues in NSX

If the expired API certificates are provided by a Custom CA, refer to  How to Replace NSX Manager Certificates Using CA-Signed Certificates in NSX 4.x

 

Additional Information

To determine the upgrade coordinator see Upgrade the Upgrade Coordinator