Error: MOZILLA_PKIX_ERROR_SELF_SIGNED_CERT when accessing VMware Cloud Director portal
search cancel

Error: MOZILLA_PKIX_ERROR_SELF_SIGNED_CERT when accessing VMware Cloud Director portal

book

Article ID: 446421

calendar_today

Updated On:

Products

VMware Cloud Director VMware Telco Cloud Platform

Issue/Introduction

  • You are unable to access the VCD portal. When navigating to the portal URL, the browser displays a security warning such as NET::ERR_CERT_AUTHORITY_INVALID or MOZILLA_PKIX_ERROR_SELF_SIGNED_CERT.
  • This occurs because the VCD portal or Load Balancer Virtual IP (VIP) is using a system default self-signed certificate.
  • Browsers do not recognise self-signed certificates as a trusted authority.
  • Additionally, cached security states or historical certificate data in the browser can prevent the manual override option from functioning.

Environment

  • VCD 10.x
  • TCP: 3, 4.x, 4.0.1, 5.x, 5.0. 5.0.1, 5.0.2

Cause

  • Browsers do not recognise self-signed certificates as a trusted authority.
  • Additionally, cached security states or historical certificate data in the browser can prevent the manual override option from functioning.

Resolution

  • Take a backup of your current certificate configuration.
  • Clear the entire browser history, including cached images and files, to remove conflicting certificate metadata.
  • Navigate to the VCD portal URL, select advanced and choose the option to proceed to the site to bypass the warning.
  • To prevent these errors permanently, apply a certificate signed by your internal Certificate Authority to the NSX-T Load Balancer.
  • Ensure the certificate includes all necessary Subject Alternative Names for both the FQDN and the VIP address.

For the detailed procedure on replacing certificates, see How to replace SSL certificates.