After you replace the certificate of the vCenter Server instance in the ROBO, replace the certificate of NSX Manager.

About this task

Table 1. Certificate-Related Files on the NSX Manager Instance in ROBO

NSX Manager FQDN

Certificate File Name

Replacement Time

nyc01nsxm01.rainpole.local

nyc01nsxm01.4.p12 from the CertGenVVD tool

After you replace the certificate on the vSphere vCenter Server

Procedure

  1. On the Windows host that has access to the data center, log in to the NSX Manager Web interface.
    1. Open a Web browser and go https://nyc01nsxm01.rainpole.local.
    2. Log in using the following credentials

      Setting

      Value

      User name

      admin

      Password

      nsx_manager_admin_password

  2. Click the Manage Appliance Settings button.
  3. On the Manage tab, click SSL Certificates and click Upload PKCS#12 Keystore.
  4. Browse to the certificate chain file, provide the keystore password or passphrase and click Import.
  5. Restart the NSX Manager to propagate the CA-signed certificate.
    1. In the right corner of the NSX Manager page, click the Settings icon. 
    2. From the drop-down menu, select Reboot Appliance.
  6. Re-register the NSX Manager to the ROBO vCenter Server.
    1. Open a Web browser and go to the NSX Manager Web interface https://nyc01nsxm01.rainpole.local.
    2. Log in using the following credentials.

      Setting

      Value

      User name

      admin

      Password

      nsx_manager_admin_password

    3. Click Manage vCenter Registration.
    4. Under Lookup Service, click the Edit button.
    5. In the Lookup Service dialog box, enter the following settings, and click OK.

      Setting

      Value

      Lookup Service IP

      nyc01vc01.rainpole.local

      Lookup Service Port

      443

      SSO Administrator User Name

      administrator@vsphere.local

      Password

      vsphere_admin_password

    6. In the Trust Certificate? dialog box, click Yes.
    7. Under vCenter Server, click the Edit button.
    8. In the vCenter Server dialog box, enter the following settings, and click OK.

      Setting

      Value for the NSX Manager for the ROBO Cluster

      vCenter Server

      nyc01vc01.rainpole.local

      vCenter User Name

      svc-nsxmanager@rainpole.local

      Password

      svc-nsxmanager_password

    9. In the Trust Certificate? dialog box, click Yes.
    10. Wait until the Status indicators for the Lookup Service and vCenter Server change to Connected.
  7. Reconnect the NSX Manager instance to vRealize Operations Manager.
    1. Open a Web browser and go to https://vrops-cluster-01.rainpole.local.
    2. Log in using the following credentials.

      Setting

      Value

      User name

      admin

      Password

      vrops_admin_password

    3. In the left pane of vRealize Operations Manager, click Administration and click Certificates.
    4. Select the row that contains CN=nyc01nsxm01.rainpole.local and click the Delete icon.
    5. In the left pane of vRealize Operations Manager, click Administration and click Solutions.
    6. From the solution table on the Solutions page, select the Management Pack for NSX-vSphere solution, and click the Configure icon at the top.
    7. In the Manage Solutions dialog box, from the Adapter Type table at the top, select NSX-vSphere Adapter.
    8. Click the nyc01nsxm01 adapter instance, click Test Connection, accept the new certificate and click Save settings.
  8. Restart vROps remote collector nodes to update the nsx certification changes.
    1. Open a Web browser and go to https://nyc01vc01.rainpole.local.
    2. Log in using the following credentials.

      Setting

      Value

      vCenter User Name

      vc_admin_user_name

      Password

      vc_admin_password

    3. From Home select Hosts and Clusters
    4. Expands NYC01-MGMT computer resources
    5. Right click on nyc01rmtcol01 and select Power -> Guest OS restart
    6. Right click on nyc01rmtcol02 and select Power -> Guest OS restart