NSX-T Certificate Management

Overview

HPE Morpheus Software provides integrated certificate management for VMware NSX-T environments. NSX-T requires certificates for securing communications between its management plane, control plane, and transport nodes. HPE Morpheus Software can manage the lifecycle of these certificates, including uploading certificates to NSX-T managers and associating them with NSX-T services.

This feature is available when an NSX-T integration has been configured in HPE Morpheus Software.

Prerequisites

  • An active NSX-T integration configured in HPE Morpheus Software (Infrastructure > Network > Integrations)

  • NSX-T Manager version 2.5 or higher

  • Appropriate NSX-T API permissions for certificate management

  • Valid SSL/TLS certificates compatible with NSX-T requirements

NSX-T Certificate Requirements

NSX-T has specific requirements for certificates:

  • Format: PEM-encoded X.509 certificates

  • Key Size: Minimum 2048-bit RSA or 256-bit ECDSA

  • Subject Alternative Names (SANs): Must include the FQDN and IP address of the NSX-T Manager nodes

  • Extended Key Usage: Server Authentication (1.3.6.1.5.5.7.3.1) and Client Authentication (1.3.6.1.5.5.7.3.2) as appropriate

  • Validity: Certificates should have sufficient validity period (recommended minimum 1 year)

Managing NSX-T Certificates

Uploading Certificates to NSX-T

When a certificate is uploaded to HPE Morpheus Software and associated with an NSX-T integration, HPE Morpheus Software handles pushing the certificate to the NSX-T Manager:

  1. Navigate to |InfTruCer|

  2. Click + ADD

  3. Select the NSX-T certificate type

  4. Complete the certificate fields:

    • NAME: Descriptive name for the certificate

    • NSX-T INTEGRATION: Select the target NSX-T integration

    • CERTIFICATE (PEM): The certificate content

    • PRIVATE KEY (PEM): The private key content

    • CERTIFICATE CHAIN (PEM): Intermediate and root CA certificates

  5. Click SAVE

HPE Morpheus Software uploads the certificate to the NSX-T Manager and stores the external reference for ongoing management.

Viewing NSX-T Certificates

Certificates synced from NSX-T integrations appear in the certificate list with their NSX-T association visible. Details include:

  • NSX-T Manager reference ID

  • Certificate purpose (e.g., API, Cluster Communication)

  • Expiration status

  • Associated NSX-T services

Replacing NSX-T Certificates

To replace an expiring certificate on an NSX-T Manager:

  1. Upload the new certificate to HPE Morpheus Software as described above

  2. Associate the new certificate with the same NSX-T service

  3. HPE Morpheus Software coordinates the replacement with the NSX-T Manager API

  4. Verify the NSX-T Manager is using the new certificate

Warning

Replacing certificates on NSX-T management and cluster services requires careful planning. Incorrect certificate replacement can disrupt NSX-T operations. Always verify certificate compatibility in a test environment first.

Certificate Synchronization

HPE Morpheus Software periodically synchronizes certificate data from NSX-T integrations:

  • Existing certificates on NSX-T are discovered and displayed in HPE Morpheus Software

  • Certificate expiration dates are tracked

  • Status changes (e.g., revocation) are reflected in the HPE Morpheus Software UI

To force a synchronization, refresh the NSX-T integration from Infrastructure > Network > Integrations.

Troubleshooting

Certificate upload fails:

  • Verify the certificate and key are in valid PEM format

  • Ensure the private key matches the certificate (modulus check)

  • Confirm NSX-T API connectivity from the HPE Morpheus Software appliance

Certificate not appearing on NSX-T:

  • Check the HPE Morpheus Software integration status for the NSX-T instance

  • Review the HPE Morpheus Software activity log for API errors

  • Verify NSX-T API user has certificate management permissions