VCF Installation Validation Fails Due to Missing CN or SAN in the NSX Manager Certificate
search cancel

VCF Installation Validation Fails Due to Missing CN or SAN in the NSX Manager Certificate

book

Article ID: 450121

calendar_today

Updated On:

Products

VMware NSX VMware Cloud Foundation

Issue/Introduction

During VCF deployment or validation, the installation fails while validating the NSX Manager. You may observe the following symptoms:

  • The VCF Installer fails during the VMware NSX validation stage.

  • SSL certificate validation for the VMware NSX Manager fails.

  • REST API communication with the VMware NSX Manager cannot be established.

  • Errors indicate that the certificate is invalid or does not meet the required validation criteria.

Environment

  • VMware Cloud Foundation 

  • VMware NSX

 

Cause

The SSL certificate installed on the NSX Manager REST API does not contain the mandatory Common Name (CN) and Subject Alternative Name (SAN) attributes required for VCF validation. As a result, VCF cannot validate the NSX Manager certificate, causing the deployment or validation process to fail.

Resolution

To resolve this issue, perform the following steps:

  1. Generate a new SSL certificate for the NSX Manager.

  2. Ensure the new certificate contains a valid Common Name (CN) or Subject Alternative Name (SAN) entry that includes the NSX Manager FQDN (and IP address, if required).

  3. Replace the existing REST API certificate on the NSX Manager using the NSX Manager UI or API.

  4. Verify that the new certificate is successfully installed.

  5. Retry the VCF validation or deployment process.

Additional Information

Replacing SDDC manager certificates with custom certs failed with " Could not resolve the hostname"

Add an SSL Certificate to the NSX Manager Node