Custom CA Certificate Replacement Fails in NSX Due to Incorrect CSR Signing Configuration
search cancel

Custom CA Certificate Replacement Fails in NSX Due to Incorrect CSR Signing Configuration

book

Article ID: 453141

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • When attempting to replace the custom CA certificate in NSX, the operation fails with error

  • Error: Attempt to import a non-CA certificate for a CA CSR. (Error code: 6110)


Environment

VMware NSX 

Cause

This issue occurs if the Signing CA Certificate option is enabled (set to "Yes") when generating the Certificate Signing Request (CSR). For standard API certificate replacement, this option must be set to "No."


Resolution

Resolution: To resolve this issue, perform the following steps to regenerate the CSR and replace the certificate:

  1. Regenerate the CSR:

    • Navigate to the CSR generation interface in your NSX environment.
    • Ensure that the Signing CA Certificate option is explicitly set to No.
    • Complete the CSR generation process with the correct parameters.
  2. Obtain and Replace the Certificate:

    • Submit the newly generated CSR to your Certificate Authority (CA) to get it signed.
    • Once the certificate is signed, use it to replace the existing self-signed API certificate of the NSX environment.

Additional Information

Download the latest patch release at Download Broadcom Products and Software.
If the issue persists, contact Broadcom Support via 
Creating and Managing Broadcom Support Cases.