HCX Service Mesh enters Unknown state with "Could not validate cert" due to duplicate appliances.
search cancel

HCX Service Mesh enters Unknown state with "Could not validate cert" due to duplicate appliances.

book

Article ID: 450039

calendar_today

Updated On:

Products

VMware HCX

Issue/Introduction

Following an infrastructure outage or ESXi host failure, the VMware HCX Service Mesh enters an unknown state post-restoring the HCX fleet appliances from a backup.

  • You see the HCX Service Mesh status as Unknown.
  • The ccli shows as disconnected status.
  • You see the error Could not validate cert for HCX appliance #### in the HCX Manager UI. 
  • Communication fails between HCX Manager and the Service Mesh appliances.

Environment

VMware HCX

Cause

An unexpected infrastructure outage can result in stale virtual machine entries or duplicate appliances in the vCenter inventory. When HCX Manager attempts to validate the certificate for a service mesh operation, it encounters a conflict between the new appliance and a stale or duplicate instance (restore from backup), causing the validation check to fail.

Resolution

Restoring HCX Fleet appliances from a backup is not supported.

  1. Log in to the vCenter Server and search for the HCX Interconnect appliances (IX and NE) associated with the Service Mesh.
  2. Identify if there are multiple appliances with the same names. 
  3. Power off and remove from inventory any duplicate or stale appliances that are not managed by the current HCX Service Mesh configuration.
  4. In the HCX Manager UI, navigate to Interconnect > Service Mesh and perform a Force Redeploy.

Workaround: If the duplicate entries cannot be easily identified, delete the affected service mesh and redeploy it to ensure a clean inventory state.