Note: PKS PI Certificate, refers to a certificate used by PKS to securely authenticate and manage NSX-T resources through its API, acting as a superuser.
VMware NSX
Client Auth' Service attached to a NSX manager node, the same NSX manager node has a valid (not expired) PKS certificate with the 'Client Auth' service.If you encounter this issue, run the CARR script attached to this KB: Using Certificate Analyzer, Results and Recovery (CARR) Script to fix certificate related issues in NSX
If the issue persists after running the CARR script, please open a support request with Broadcom NSX support and reference this KB.
If you are opening a support request, please provide the carr.log after running the script:
Related Articles:
How to renew the nsx-t-superuser-certificate used by Principal Identity user