In a VMware NSX Federation environment, Global Manager (GM) instances may fail to connect to Local Manager (LM) locations. This results in the site status appearing as Disconnected in both sites' NSX UI, preventing the synchronization of networking entities across the federation.
2026-07-10T16:49:01.938Z <FQDN> NSX 73187 - [nsx@6876 comp="global-manager" subcomp="appl-proxy" s2comp="nsx-net" tid="<ID>" level="ERROR" errorCode="NET1111"] Certificate validation failed: 10-certificate has expiredVMware NSX 4.2.x
The issue is caused by a stale certificate binding within the Appliance Proxy Hub (APH) service. Even when an expired CA-signed certificate is marked for deletion in the UI, the APH service may maintain an active binding to it, blocking the full removal and preventing the service from using newer certificates.
Additionally, this failure can be compounded if newly imported CA-signed certificates lack the required Subject Alternative Names (SANs) for all managers in the federation, which are mandatory for secure cross-site communication.
To resolve this issue, you must manually release the APH service lock using self-signed certificates and then re-apply valid CA-signed certificates.
Remediate APH Service Binding:
Force Management Plane Cache Refresh:
Restore Correct CA-Signed Certificates:
Update Federation Site Connection: