Message: Certificate validation failed for NSX-FQDN witherror { "status" : "REJECTED? "error_message" : “Certificate was rejected:KeyUsage does not allow key encipherment" }Remediation Message:Reference Token:
VMware Cloud Foundation 9.x
When replacing an expired or expiring certificate with a custom CA-signed certificate, the NSX Manager API validation explicitly rejects the payload if the KeyUsage extension does not allow key encipherment. The validation engine mandates this attribute to facilitate secure TLS handshakes.
keyUsage = digitalSignature, keyEncipherment` in CA templates).For additional information visit the documentation Managing Certificates in VMware Cloud Foundation
For additional information on NSX certificate visit the documentation Import a Self-signed or CA-signed Certificate for NSX