NSX upgrade precheck incorrectly flags NAPP_Platform certificate as a stale
search cancel

NSX upgrade precheck incorrectly flags NAPP_Platform certificate as a stale

book

Article ID: 451516

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • NSX upgrade precheck throws error for NAPP_Platform certificate strating "Invalid or self-signed certificate with expiry less than 825 days detected"

  • Upon checking the certificate, you may see that this is valid certificate
  • CARR script fails to release this certificate with logs (/var/log/carr/carr.log) indicating this as a stale certificate

026-07-15 17:26:49,006 - carr.recovery.stale_certs_removal_task - MainThread - INFO - stale_certs_removal_task.py:63 - Releasing stale cert - id : ########-8a46-####-baeb-############ for node id: NAPP Platform and service type: NAPP_Platform.

 

Environment

VMware NSX

Cause

NSX doesn't have a certificate profile for "NAPP_Platform" as recognized service type and PUB CARR script incorrectly detecting a certificate tied to "NAPP_Platform" service as stale certificate.

The allowed service types are : NAPP_COMMON_AGENT, NAPP_PACE_AGENT, NAPP_METRICS_AGENT

Resolution

If you believe you have encountered this issue and are unable to upgrade, please open a support case with Broadcom GS and refer to this KB article. 

For more information, see Creating and managing Broadcom support cases.