Effects on NSX if the vCenter VMCA root certificate is replaced from self-signed to a CA signed certificate
search cancel

Effects on NSX if the vCenter VMCA root certificate is replaced from self-signed to a CA signed certificate

book

Article ID: 432276

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

You are looking to replace VMCA root certificate from a self-signed to a CA signed certificate and you are seeking to know it's effects from NSX perspective and this KB provides information on impacts of VMCA root certificate replacement in NSX perspective specifically and not the impacts it may have on the VC itself or the ESXi's.

Environment

VMware NSX

Resolution

  • NSX supports both self-signed and CA-signed certificates for vCenter VMCA root replacement, however, it validates the vCenter connection using a specific thumbprint.
  • If this certificate is replaced, the Compute Manager will show a "Down" status until the new thumbprint is updated in the NSX UI under System > Fabric > Compute Managers.
  • With Compute Manager being down during the activity, there maybe impacts on realization of new objects created in NSX, edit of existing objects etc., 

Note: As with any changes, replacing VMCA certificate is recommended over a maintenance window.

As mentioned above, this KB only talks about impacts of replacing VMCA root certificate from NSX perspective and for guidance on impacts relating to VC itself and ESXi's, please open a case with Broadcom Support team for validation and for any further queries on impacts or issues faced during or after VMCA certificate replacement.

Additional Information

Follow the below KB to resolve the thumbprint mismatch issue after the vCenter certificate replacement.
After the vCenter Server certificate is replaced, the compute manager connection is "Down" in the NSX UI