Error 90011 "Failed to enable trust on Compute Manager" in NSX after vCenter Server certificate replacement
search cancel

Error 90011 "Failed to enable trust on Compute Manager" in NSX after vCenter Server certificate replacement

book

Article ID: 443876

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

Environment

VMware NSX 4.x

VMware vSphere 8.x

Cause

During the thumbprint replacement in NSX the deletion of the old endpoint record is successful but the creation of the new endpoint record fails, because the thumbprint values for the certificate presented on different ports of the vCenter Server is mismatching.

This can be caused by a firewall or proxy handling the HTTPS connectivity between the vCenter Server and the NSX manager nodes, such as by injecting different certificate data for security or inspection purposes, or by caching the original certificate for the vCenter.

Resolution

Disable the NSX managers' HTTPS proxy from System > General Settings in the NSX UI.

Additional Information

If there is no proxy configuration set on the NSX managers, check instead for situations where the vCenter Server's new certificate was not applied to all of its outgoing services.