NSX Compute Manager connection down due to vCenter certificate thumbprint mismatch
search cancel

NSX Compute Manager connection down due to vCenter certificate thumbprint mismatch

book

Article ID: 446711

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

The NSX Compute Manager registration fails, and the connection status remains "Down." The following alert is generated:

  • The certificate for the Compute Manager has expired or is invalid.

Environment

  • VMware NSX 
  • VMware vCenter Server 

Cause

The vCenter Server reports a thumbprint that does not match the certificate provided by the issuer. This mismatch prevents successful authentication and registration between NSX and the vCenter Server. This inconsistency is typically found within the vCenter certificate chain and store, often following a certificate update or environment change where the active thumbprint becomes out of sync with the issuer's certificate.

Resolution

To resolve this issue, you must issue and apply a new custom certificate to the vCenter Server to synchronize the certificate chain and then update the thumbprint in NSX.

  1. Generate and apply a new vCenter custom CA signed certificate by following Updating custom certificates for vCenter from vSphere Client
  2. Once the vCenter certificate installation wizard has completed the certificate update, re-register the Compute Manager in NSX UI. 
    Log into the NSX UI and go to System > Fabric > Compute Managers in the NSX Manager UI
    Click the check box next to your vCenter Server and select Edit.
    Re-enter the vCenter administrative Username and Password
    A prompt will appear highlighting the changed certificate. Review and accept the new thumbprint.
    Click Save and verify the status changes to Up/Connected. 
  3. Confirm the Compute Manager is now registered and connected.

If the above steps do not resolve the issue, open a case with Broadcom Technical support. Contact Broadcom support

Additional Information

NSX Compute Manager 'Connection Status' Down

NSX error "Certificate chain of compute manager "VC-FQDN"/"VC-shortname" is invalid (Error code: 90204)

Compute Manager Connection Status Down with Invalid Credentials or Extensions Not Valid Error