Mastering the /v1/credentials API in SDDC Manager for Enhanced Security Management

In the rapidly evolving landscape of VMware’s Cloud Foundation, security management is a cornerstone for maintaining the integrity and confidentiality of the software-defined data center (SDDC). The SDDC Manager, a critical component of VMware’s Cloud Foundation, offers a comprehensive suite of APIs for managing various aspects of the SDDC, including credentials management. This blog post delves into the specifics of leveraging the /v1/credentials API in SDDC Manager, offering a detailed guide for VMware professionals to enhance their security posture through efficient credentials management. ...

Mastering the /v1/credentials API in SDDC Manager for Enhanced Security Management
URL path for an SDDC Manager task in the API Explorer.

Canceling a Running Task in SDDC Manager with the Supported API

SDDC Manager exposes a supported Tasks API for canceling some running workflows. The important word is some: a task must be in the IN_PROGRESS state and its task record must report isCancellable: true. Cancellation is not a rollback. Work already completed by the task can remain in place. This guide uses only the public /v1/tasks and /v1/tokens endpoints documented in the current SDDC Manager API, reviewed against the VCF 9.x API selector on August 25, 2026. For an older VCF release, confirm that release’s API Explorer exposes the same operations and schema before using the commands. It does not delete internal task registrations or modify SDDC Manager’s database. ...

 · Updated  · 
Canceling a Running Task in SDDC Manager with the Supported API
Expired certificate warning, options to import or generate new.

Replacing the idps reporting Corfu certificate in NSX

In this blog we will go over replacing the idps reporting Corfu certificate in NSX Corfu certificate in NSX. In this example I will be using the UI to generate the self signed certificate and then an API call to replace the certificate. Identifying the Expired Certificate In my case the cluster manager Corfu certificate has already expired Generating a New Self-Signed Certificate In the top menu bar I went to Generate -> Generate Self Signed Certificate ...

Replacing the idps reporting Corfu certificate in NSX
Expired certificate details for NSX cluster manager Corfu client.

Replacing the cluster manager Corfu certificate in NSX

In this blog we will go over replacing the cluster manager Corfu certificate in NSX. In this example I will be using the UI to generate the self signed certificate and then an API call to replace the certificate. In my case the cluster manager Corfu certificate has already expired Generating a Self Signed Certificate In the top menu bar I went to Generate -> Generate Self Signed Certificate ...

Replacing the cluster manager Corfu certificate in NSX
Expired Monitoring Corfu certificate with details and error.

Replacing the Monitoring Corfu certificate in NSX

I replaced the expired Monitoring Corfu certificate in NSX by generating a self-signed certificate in the UI and sending the replacement through the API. In my case the Monitoring Corfu certificate has already expired Generating a Self-Signed Certificate In the top menu bar I went to Generate -> Generate Self Signed Certificate ...

Replacing the Monitoring Corfu certificate in NSX
Expired certificate alert shown for CSM Corfu client certificate.

Replacing the CSM Corfu certificate in NSX

I replaced the expired CSM Corfu certificate in NSX by generating a self-signed certificate in the UI and sending the replacement through the API. I covered the same procedure for the MP Corfu certificate and the CCP Corfu certificate in separate posts. The Expired CSM Corfu Certificate In my case the CSM Corfu certificate has already expired Generating a New Self-Signed Certificate In the top menu bar I went to Generate -> Generate Self Signed Certificate ...

Replacing the CSM Corfu certificate in NSX
Expired GM Corfu certificate details with expiration date.

Replacing the GM Corfu certificate in NSX

This walkthrough covers a targeted replacement of a node-scoped Global Manager (GM) Corfu certificate. The screenshots were captured on NSX 4.1.0.2; the exact UI differs in later releases. Version and safety note: On NSX 4.2.x and VCF NSX 9.x, Broadcom prefers the built-in NSX Manager certificate-replacement UI. For a broader self-signed-certificate assessment or recovery, use the current Certificate Analyzer, Results and Recovery (CARR) procedure. CARR requires a dry run before remediation. Use the API below only when a targeted GM Corfu binding is appropriate for the installed release. ...

 · Updated  · 
Replacing the GM Corfu certificate in NSX
Expired certificate warning shown for MP Corfu Client certificate.

Replacing the MP Corfu certificate in NSX

I replaced the expired MP Corfu certificate in NSX by generating a self-signed certificate in the UI and sending the replacement through the API. In my case the MP Corfu certificate has already expired Generating a New Self-Signed Certificate In the top menu bar I went to Generate -> Generate Self Signed Certificate ...

Replacing the MP Corfu certificate in NSX
CCP-Corfu Client certificate expired on July 18, 2022.

Replacing the CCP Corfu certificate in NSX

I replaced the expired CCP Corfu certificate in NSX by generating a self-signed certificate in the UI and sending the replacement through the API. In my case the CCP Corfu certificate has already expired Generating a Self-Signed Certificate In the top menu bar I went to Generate -> Generate Self Signed Certificate Next I had to grab the new certificate ID ...

Replacing the CCP Corfu certificate in NSX
Expired certificate alert in NSX UI, showing AR Corfu client certificate details.

Replacing the AR Corfu certificate in NSX

I replaced the expired AR Corfu certificate in NSX by generating a self-signed certificate in the UI and sending the replacement through the API. Identifying the Expired AR Corfu Certificate In my case the AR Corfu certificate has already expired Generating a Self-Signed Certificate in the NSX UI In the top menu bar I went to Generate -> Generate Self Signed Certificate ...

Replacing the AR Corfu certificate in NSX