Tomcat : for external communication from nsx manager nodes
mpc luster: for external communcation from nsx manager to nsx manager cluster.
local manager : for nsx federation account
by default these there certificate are valid till 825days .
1. Login to NSX Manager
2. Go to System -> certificate
data:image/s3,"s3://crabby-images/d9160/d9160adca0cf01d3f8793e8c4ed144f51a2822e4" alt=""
3. Once you verify the Certificate validation for Mpcluster , tomcat and localManager . then proceed for the replacement of the certs , Here i am trying to replace the Certificate for localManager which is going to expire Aug 15 2025 .
data:image/s3,"s3://crabby-images/1fb24/1fb24dd1f6e5f7f56a71b2f2dcefc46865e581d3" alt=""
4. Generate the CSR Using the existing information and Click Generate
data:image/s3,"s3://crabby-images/690ec/690ec1c28b20eafd2a579e1753d8e2f2941350af" alt=""
5. Now click on the CSR which you have generated in step 4 , in my case its for localManager.
6. Select LocalManager -> Action-> Self sign certificate for CSR - >
keep 825 days default value and click Save
data:image/s3,"s3://crabby-images/55ec0/55ec06d09611868851c25bd3a8f61473be8da758" alt=""
data:image/s3,"s3://crabby-images/faaa0/faaa03f70e5f88a4d783a17772f991654e7fac3c" alt=""
7. once the certificate is created , if we go into the Certificate tab , we will see two certs for localManager. one with old version and one with new one which we created.
data:image/s3,"s3://crabby-images/b502e/b502e6b003a2f14c2f53ff05af5db77688ea5101" alt=""
8. Download postman for publishing the certificate .
9. open postman -> create new request
10. Keep params default
11. Authorization : ender admin and password
data:image/s3,"s3://crabby-images/4532f/4532f3d91572a1f331e4fa7420c46291f1ad5421" alt=""
12. Headers : enter value as application\json
data:image/s3,"s3://crabby-images/bdec2/bdec2bf9cdf7db31cb72151aa492bd28a2b96946" alt=""
13. Under Body select radio button on raw and JSON
{ "cert_id": "certificate 6df5417c-a6f5-43bf-82d4-c9cd0131cc77",
"service_type": "LOCAL_MANAGER" }
data:image/s3,"s3://crabby-images/36d45/36d4545f564e2c7c0a6c1a3999edd6cb5faeff4c" alt=""
how to find Certificate Id : Login to the NSX-> Certificate -> Newly Created Certificate expand it u will see the ID as show below.
data:image/s3,"s3://crabby-images/3e0cf/3e0cf270048f7d2d0693116df929503e923f89d4" alt=""
16. Click on Send , this will pass the certificate to nsx manager .
Comments