This article clarifies the steps of replacing or renewing the NSX-V Manager SSL certificate and its impact on active NSX Edge services. When managing business-critical production environments, ensuring that certificate rotation does not disrupt Load Balancer (LB) or VPN traffic is essential for maintenance planning.
Symptoms:
Replacing the NSX-V Manager certificate has no data plane impact on active NSX Edge services such as Load Balancer or VPN traffic. The NSX Edge appliances utilize independent "Service Certificates" managed via Policy APIs, which are technically isolated from the Management Plane "Appliance Certificate" used by the NSX Manager.
Follow these steps to replace the certificate via the GUI:
Note: Expected alerts regarding Edge connectivity to the Manager or Spoofguard may appear during the Manager reboot process. These alerts are transient and do not indicate a data plane service interruption.