Federated NSX environment
In an NSX Federation environment, the Global Manager maintains a remote reference to Local Manager certificates via Principal Identities (PI). These remote entries typically do not contain the private key on the GM. Because the CARR script's discovery logic focuses on certificates where the private key is held locally, it may skip these remote references during a GM-only run.
Furthermore, the NSX UI may not surface localized truststore inconsistencies or site-specific certificate integrity issues that are only visible when the script performs its mandatory integrity checks directly on the Local Manager cluster.
./start.sh -d to generate the site-local validation_config_recovery_mode.yaml../start.sh.