In VMware NSX, a certificate-expired alarm may remain in an OPEN state on a Local Manager or Global Manager even when the certificate inventory does not contain any expired certificates.
Symptoms:
VMware NSX
The issue is typically caused by a stale alarm record in the NSX Alarm database. This occurs when a certificate that was previously present and expired has been deleted or replaced, but the associated alarm was not automatically cleared or suppressed by the system. Because the certificate object no longer exists, the system cannot perform a state check to "auto-resolve" the alarm.
phonehome-coordinator service on all the manager nodes/etc/init.d/phonehome-coordinator status #Check the status of phonehome-coordinator/etc/init.d/phonehome-coordinator restart #Restart the phonehome-coordinator serviceproton service on all the NSX manager nodes. /etc/init.d/proton status #Check the status of proton service/etc/init.d/proton restart #Restart the proton serviceIf issue persists, collect all the 3 NSX Manager node log bundles and open a support request with Broadcom.