When updating SSL/TLS certificates in a multi-cell VMware Cloud Director environment, the deployment becomes unstable or encounters errors when attempting to apply updates or perform cluster failovers using standby cells.
The certificate update only succeeds when applied directly to the active primary cell. Subsequent failover operations to a standby cell fail or leave the standby node unusable.
VMware Cloud Director 10.x
Standby cells cannot properly bind or synchronize updated cluster-wide certificate stores while in a secondary role. Modifying standby nodes directly bypasses the expected appliance configuration workflows driven by the primary cell, resulting in database and configuration state desynchronization upon failover
To resolve the failure and restore cluster stability, update the primary node first and redeploy the standby nodes so they receive a clean, synchronized state:
Log in to the active primary VMware Cloud Director cell.
Update the SSL/TLS certificate on the primary cell via the Provider UI or CLI.
Unregister and remove the unstable standby cells from the Cloud Director cluster. Unregister a Running Standby Cell in Your VMware Cloud Director Database High Availability Cluster
Deploy new standby cell. The newly created standby nodes will automatically pull and apply the correct certificate configuration from the primary node. VMware Cloud Director Appliance Deployments and Database High Availability Configuration
Verify cluster health and perform a test failover to confirm standby cell stability.