NSX Manager system overview displays vCenter certificate without a private key
search cancel

NSX Manager system overview displays vCenter certificate without a private key

book

Article ID: 446249

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

In VMware NSX, the system overview displays one certificate without a private key. Clicking on this certificate without a private key redirects to the vCenter Server certificate

Environment

  • VMware Cloud Foundation 9.x
  • VMware NSX 9.x

Cause

This is expected and normal behavior. When a vCenter Server is added as a "Compute Manager" in NSX, NSX must establish a secure, trusted connection to it. To achieve this, NSX imports the vCenter's root CA certificate (VMCA) to trust the certificates presented by vCenter. NSX only requires the public certificate to verify that trust and, by security design, should never possess the vCenter's private signing key.

Resolution

  • No action is required; the system is operating exactly as designed.

  • Because NSX is establishing trust with the vCenter Server as a Compute Manager, retaining only the public certificate is the correct security posture.

  • The private key remains securely on the vCenter Server, verifying that this behavior is architecturally sound and requires no remediation.