Host transport node preparation Fails after NSX Manager API Certificate Replacement.
search cancel

Host transport node preparation Fails after NSX Manager API Certificate Replacement.

book

Article ID: 443321

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

When attempting to prepare or install NSX components on ESXi hosts within a vSphere Lifecycle Manager (vLCM) cluster, the installation task fails.

  • The issue occurs immediately after replacing the NSX Manager API certificates with Custom CA or vSphere Certificate Authority (VMCA) signed certificates.

  • The host status in the NSX Manager UI displays an installation  failure with error "Failed to install software on host. NSX Manager nsxmgr.XXX.net has invalid API certificate. Error: (51) SSL:no alternative certificate subject name matches target host name 'host.XXXXXX.net'. Fix the certificate issue on NSX Manager and retry the operation."

  • The vLCM remediation workflow stalls or cannot establish a trusted connection to the manager cluster during host staging.

Environment

VMware NSX

Cause

The certificate assigned to the NSX Manager is missing the required DNS name entries within the Subject Alternative Name (SAN) field.

When vLCM initiates host preparation, the ESXi host attempts to validate the identity of the NSX Manager via its fully qualified domain name (FQDN). If the FQDN/DNS entry is not explicitly defined in the certificate's SAN field, the connection fails the strict validation check.

As a result, the host cannot securely pull the required installation files, preventing the remediation from completing.

Resolution

To resolve this issue, the NSX Manager API certificate must be reissued or replaced with a certificate that contains the correct SAN details, including all relevant DNS names and IP addresses.

If a Certificate Authority (CA) is not immediately available to sign a new Certificate Signing Request (CSR), a self-signed certificate can be generated directly within NSX with the required SAN fields:

Additional Information

If you are contacting Broadcom support about this issue, please provide the following:

  • NSX Manager support bundles.

  • A text export or screenshot of the current certificate details showing the Subject and SAN fields.

  • Specific error text displayed within the vLCM task monitor or host log extracts.

Handling Log Bundles for offline review with Broadcom support: