NSX-V Manager certificate replacement and its impact
search cancel

NSX-V Manager certificate replacement and its impact

book

Article ID: 448372

calendar_today

Updated On:

Products

VMware NSX Data Center for vSphere

Issue/Introduction

This article clarifies the steps of replacing or renewing the NSX-V Manager SSL certificate and its impact on active NSX Edge services. When managing business-critical production environments, ensuring that certificate rotation does not disrupt Load Balancer (LB) or VPN traffic is essential for maintenance planning.

Symptoms:

  • Need to replace the NSX Manager certificate using a self-signed or CA-signed certificate via the GUI.
  • Concerns regarding potential downtime for NSX Edge appliances during the Manager certificate swap or subsequent Manager reboot.

Environment

  • VMware NSX for vSphere 6.4.x
  • VMware vSphere 7.x
  • VMware vSphere 6.x

Resolution

Replacing the NSX-V Manager certificate has no data plane impact on active NSX Edge services such as Load Balancer or VPN traffic. The NSX Edge appliances utilize independent "Service Certificates" managed via Policy APIs, which are technically isolated from the Management Plane "Appliance Certificate" used by the NSX Manager.

Follow these steps to replace the certificate via the GUI:

  1. Create a backup of the NSX Manager.
  2. Log in to the NSX Manager virtual appliance.
  3. Navigate to Manage Appliance Settings > Settings > SSL Certificates.
  4. Select Self sign CSR and apply certificate or upload the desired CA-signed certificate.
  5. Click OK to apply the changes.
  6. Reboot the NSX Manager appliance to complete the initialization.
  7. Verify the status of Edges, Controllers, and Hosts in the NSX Dashboard to ensure all components return to a GREEN status.

Note: Expected alerts regarding Edge connectivity to the Manager or Spoofguard may appear during the Manager reboot process. These alerts are transient and do not indicate a data plane service interruption.

Additional Information

VMware NSX for vSphere Documentation