NSX manager keep failing at the same pre-check error "Invalid or self-signed certificates with expiry less than 825 days detected" even after giving RESOLVE action
search cancel

NSX manager keep failing at the same pre-check error "Invalid or self-signed certificates with expiry less than 825 days detected" even after giving RESOLVE action

book

Article ID: 449722

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • You are facing below certificate error while running the upgrade precheck

  • Applying RESOLVE action did not fix the issue and it keeps falling into the same error

Environment

VMware NSX

Cause

In NSX 4.2 and later, the upgrade coordinator integrates the Certificate Analyzer Resolver (CARR) logic directly into the pre-upgrade checks. When the precheck identifies a certificate that violates the 825-day validity policy (such as LOCAL-MANAGER-PI or CBM-Corfu), clicking Resolve triggers an automated process to generate and apply a new certificate that meets the current security requirements. While the Resolve button is effective for most internal self-signed certificates, it may not fix everything:

Resolution

Run CARR script manually. Refer KB:  Using Certificate Analyzer, Results and Recovery (CARR) Script to fix certificate related issues in NSX which should ideally fix the above issue.

If it is still failing to the same error and not able to complete the precheck

Please open a support case with Broadcom and refer to this KB article. 

For more information Refer: Creating and managing Broadcom cases

Additional Information

NSX Manager upgrade fails with certificate expiry less than 825 days error in SDDC Manager

Execute CARR Script fails with 825-day validity requirement and CSR generation failure on SDDC Manager

Transport Node certificates expiring within 825 days warning during NSX Manager upgrade pre-check