The NSX Manager UI displays persistent, repeating alarms indicating that the vSphere ESX Agent Manager (EAM) service is down or disconnected.
The alarm triggers precisely every 3 minutes.
When validating the EAM service status within the linked vCenter Server, the service is found to be running normally and reported as "Up".
This issue may occur across multiple independent NSX instances linked to the same vCenter Server.
[nsx@6876 comp="nsx-manager" level="INFO" subcomp="manager"] checkServerTrusted: CN=##############.com for authType=ECDHE_RSA failed: ################################################
NSX 5461 SYSTEM [nsx@6876 comp="nsx-manager" errorCode="MP40451" level="ERROR" subcomp="manager"] Error occured while fetching eam status for cmId ##########################, com.vmware.vim.vmomi.client.exception.SslException: javax.net.ssl.SSLHandshakeException: ################################################
[nsx@6876 comp="nsx-manager" level="WARNING" subcomp="manager"] Thumbprint mismatch for ################################################
VMware NSX
The root cause of this alert loop is a Compute Manager certificate thumbprint mismatch after vCenter certificate replacement.
Every 3 minutes, the NSX Manager performs a scheduled health poll to check the EAM status from the Compute Manager (vCenter Server).
If the security certificate on the vCenter Server has been replaced or updated, its cryptographic thumbprint changes.
Update the Compute Manager registration to trust the new certificate:
Log in to the NSX Manager UI.
Navigate to System > Fabric > Compute Managers.
Select the affected vCenter Server (Compute Manager) and click Edit.
To force a refresh of the certificate attributes, you can choose to click Save directly or input the updated certificate details if prompted.
A dialogue box will appear displaying the new certificate thumbprint provided by the vCenter Server. Click Resolve or Trust to accept the new thumbprint and update the registration.
If you are contacting Broadcom support about this issue, please provide the following:
NSX Manager support bundles.
The current SHA-256 certificate thumbprint string directly copied from the vCenter Server management interface.
Specific error details present in the NSX Manager UI under the Alarm logs.
Handling Log Bundles for offline review with Broadcom support: