How to renew Self-Signed certificates for NSX-T LocalManager, tomcat and mp-cluster.
Hello Everyone, Hope you are doing well. Today, i am covering this posts regarding the self-signed certificate expires in NSX-T environments for components like LocalManager and mp-cluster. you will see warnings on NSX-T GUI that LocalManager and mp-cluster self-signed certificates has been expired. Generally, we update only NSX Manager Cluster/VIP certificates only. Certificates for LocalManager, tomcat and mp-cluster comes with self-signed certificates when we deployed the NSX-T environment. tomcat certificates is an API certificate used for external communication with individual NSX Manager nodes through UI/API. mp-cluster is an API certificate used for external communication with the NSX Manager cluster using the cluster VIP, through UI/API. Let's start to renew the LocalManager self-signed certificates. Login to NSX-T GUI with admin credentials. Go to Systems > Under Settings click on Certificates > click on CSRs > click GENERATE CsR Click on GENERATE . CSR for