VCF Operations HCX 9.1.0.0 import fails with CN/SAN mismatch error
search cancel

VCF Operations HCX 9.1.0.0 import fails with CN/SAN mismatch error

book

Article ID: 445282

calendar_today

Updated On:

Products

VMware HCX

Issue/Introduction

Importing an HCX 9.1.0.0 appliance into VCF Operations fails with a Common Name (CN) / Subject Alternative Name (SAN) mismatch error. This occurs when the HCX appliance uses self-signed or custom certificates that lack a SAN field.

Environment

VCF Operations 9.1.0.0 

HCX Manager  9.1.0.0 

Cause

VCF Operations 9.1.0.0 mandates the presence of a SAN in the appliance certificate.

HCX Manager versions prior to 9.1.0.0 often generated self-signed certificates without SAN, and custom certificates may also lack this field if not properly configured.

Resolution

Update the certificates to include a valid SAN:
Refer KB Replace HCX 443 UI certificate with custom CA
Note: If custom certificates were used please update with SAN and reapply on the upgraded HCX Managers