VMware NSX
The CARR (Certificate Analyzer, Results and Recovery) script is designed to resolve issues with self-signed certificates. It does not interact with CA-signed certificates to prevent breaking existing security compliance or external trust chains.
If your deployment does not mandate a fully trusted external CA, you can resolve the expiration alarm by either generating new CA signed certificates externally and following the documented steps to replace the expiring certificate with these new certificates Admin Guide - Replace Certificates via GUI or Admin Guide - Replace certificates via API
Alternatively the API and VIP certificates can be replaced by the VCSA scripted approach Scripted process to replace expired or self-signed VMware NSX Manager Certificates with VMCA-Signed Certificates . This will be a VCSA signed certificate.
If a CA signed cert is not required, the existing expiring CA signed cert can be replaced with a self signed cert via the GUI. Follow these steps to do so :