This series collects the NSX internal certificate replacement procedures documented in July 2023. Start with the certificate’s name and affected service in your environment, then use the corresponding walkthrough to understand the UI and API operations shown.
Choose the affected service
| Certificate or service | Walkthrough |
|---|---|
| Corfu API | Replace the Corfu API certificate |
| AR | Replace the AR Corfu certificate |
| CCP | Replace the CCP Corfu certificate |
| CSM | Replace the CSM Corfu certificate |
| GM | Replace the GM Corfu certificate |
| MP | Replace the MP Corfu certificate |
| Cluster Manager | Replace the Cluster Manager Corfu certificate |
| Monitoring | Replace the Monitoring Corfu certificate |
| IDPS Reporting | Replace the IDPS Reporting Corfu certificate |
These are version-specific examples. Confirm the procedure in the NSX documentation for your installed release, identify the correct certificate and node IDs, and prepare the required backup and recovery plan before a replacement. Do not assume the same API or service identifier applies to every certificate.
If deletion reports that a certificate is still used by a management-plane node, see the MP node certificate association investigation. More administration and VCF integration topics are in the NSX guides.








