After you replace the certificate on the vCenter Server instance, replace the certificate for the NSX Manager instance.

About this task

Table 1. Certificate-Related Files on the NSX Manager Instances in Region A

NSX Manager FQDN

Certificate File Name

Replacement Time


  • nyc01nsxm01.4.p12 from the automation generation

Right after deployment of NSX Manager instance


  1. On the Windows host that has access to the data center, log in to the NSX Manager Web interface.
    1. Open a Web Browser and go to following URL https://nyc01nsxm01.rainpole.local
    2. Log in using the following credentials.



      User name




  2. Click the Manage Appliance Settings button.
  3. On the Manage tab, click SSL Certificates and click Upload PKCS#12 Keystore.
  4. Browse to the certificate chain file, provide the keystore password or passphrase and click Import.
  5. In the right corner of the NSX Manager user interface, click the Settings icon. 
  6. From the drop-down menu, select Reboot Appliance.

    The NSX Manager restarts, which in turn propagates the CA-signed certificate.