NSX Manager certificates replacement using SDDC Manager and VMCA in VCF 5.x
search cancel

NSX Manager certificates replacement using SDDC Manager and VMCA in VCF 5.x

book

Article ID: 449294

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

NSX Manager API or VIP cluster certificates are nearing expiration. To maintain trust and management functionality, these must be rotated via SDDC Manager before they expire.

Resolution

  1. Log in to the SDDC Manager UI.
  2. Navigate to Inventory > Workload Domains and click the name of the target domain.
  3. Select the Certificates tab.
  4. Select the checkbox for the NSX Manager resource type.
  5. Click GENERATE CSRS.
  6. In the Subject Alternative Name (SAN) dialog, enter the following (separated by comma, semicolon, or space):
    • FQDN of NSX-Node-1
    • FQDN of NSX-Node-2
    • FQDN of NSX-Node-3
    • FQDN of NSX-Cluster-VIP
    • (Recommended) IP addresses for all three nodes and the VIP.
  7. Once the CSR is generated, click GENERATE SIGNED CERTIFICATES to have SDDC Manager request the signatures from the vCenter VMCA
  8. Click INSTALL CERTIFICATES to apply them to the NSX nodes.
  9. Repeat for all four certificates in the NSX management cluster.

Additional Information

If the NSX Manager certificate has expired, please refer to the KB article https://knowledge.broadcom.com/external/article/317900/scripted-process-to-replace-expired-or-s.html