SSL trust errors and unable to connect Cisco Secure Dynamic Attributes Connectors to VMware NSX / vCenter environment
search cancel

SSL trust errors and unable to connect Cisco Secure Dynamic Attributes Connectors to VMware NSX / vCenter environment

book

Article ID: 449877

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • When attempting to follow Create a vCenter Connector the creation and validation of the connector fails for the combined NSX/vCenter configuration.
  • The error states SSL trust failures when fetching or adding certificates, however does not specify which part of the config has failures.

Environment

  • VMware NSX
  • VMware vCenter Server
  • Cisco Firepower / Cisco Secure Dynamic Attributes Connector (CSDAC)

Cause

The configuration in the Cisco components contains both NSX and vCenter. As part of this configuration the certificates are fetched from the VMware components or provided manually by the user. The SSL/TLS certificates installed on vCenter Server and NSX require Subject Alternative Name (SAN) attributes and the complete CA trust chain in order to be valid within the connector configuration. If the certificates are not SAN configured or the entire chain is not presented, trust may fail.

 

Resolution

The certificates need to be configured in vCenter and NSX to meet the Cisco requirements of having the FQDN of the component within the SAN field of the certificates used by following the below steps, alternatively an external CA certifcate can be generated and imported.

If certificates are replaced with SAN configured ones and issues remain, Cisco support should be engaged to assist and review the cause of the connector trust failure, if advised then VMware support can be engaged. 

Additional Information

Cisco CSDAC-Create a vCenter Connector