This validation error typically occurs during the Validate and Deploy phase of a VMware Cloud Foundation (VCF) installation, particularly when VCF attempts to register or connect to the existing NSX Manager cluster.
VMware NSX
The core issue lies with the certificate presented by the NSX Manager Management Cluster Virtual IP (VIP) and/or API Services—which is the endpoint VCF Installer is trying to connect to (e.g., nsxmanager.example.com).
When VCF attempts to validate the fully qualified domain name (FQDN) of the NSX Manager cluster (e.g., nsxmanager.example.com) and/or individual NSX Manager nodes, it checks the certificate's Subject Alternative Name (SAN) field.
The certificate configured on the NSX Manager VIP (the MGMT_CLUSTER and REST API (API) endpoints) only contains the short name (or a different, incorrect name) of the NSX Manager in its SAN list, such as [nsxmanagershortname].
Because the requested FQDN (nsxmanager.example.com) does not match any entry in the certificate's SAN list, the connection fails with a certificate mismatch error, causing the VCF validation to halt.
The resolution is to replace the certificate on the NSX Manager Management Cluster (MGMT_CLUSTER) VIP and/or NSX Manager Nodes REST API (API) Services with a new one that correctly includes the FQDN (nsxmanager.example.com) in the Subject Alternative Name field.
Applying a single certificate to all NSX Manager nodes REST API (API) and the MGMT_CLUSTER VIP is only possible if the SAN entries in the CSR include all nodes and the VIP.
nsxmanager.example.com) in the Subject Alternative Name field.