VMware NSX
In NSX 4.2 and later, the upgrade coordinator integrates the Certificate Analyzer Resolver (CARR) logic directly into the pre-upgrade checks. When the precheck identifies a certificate that violates the 825-day validity policy (such as LOCAL-MANAGER-PI or CBM-Corfu), clicking Resolve triggers an automated process to generate and apply a new certificate that meets the current security requirements. While the Resolve button is effective for most internal self-signed certificates, it may not fix everything:
Run CARR script manually. Refer KB: Using Certificate Analyzer, Results and Recovery (CARR) Script to fix certificate related issues in NSX which should ideally fix the above issue.
If it is still failing to the same error and not able to complete the precheck
Please open a support case with Broadcom and refer to this KB article.
For more information Refer: Creating and managing Broadcom cases