`Failed to update user credential in Avi Load Balancer Controller Cluster. Cause: InvalidRequest (com.vmware.vapi.std.errors.invalid_request) (statusCode:400) => {error_message=I/O error on POST request for "https://<avi_controller_ip>/api/authtoken": Certificate expired for CN=<avi_controller_fqdn>; nested exception is javax.net.ssl.SSLHandshakeException: Certificate expired...
To resolve this issue, the Avi Controller certificate must be renewed manually before the password rotation can be synchronized in SDDC Manager
Prepare the new CA-signed certificate and its corresponding private key.
Note: This is supported by the AVI Load Balancer support tea. If assistance is needed open a case with the AVI team.
If the password for the service account has already expired locally on the Avi Controller:
For environments where the NSX Manager still reports the Avi Controller as "Not Reachable" after certificate replacement, refer to: