NSX Advanced Load Balancer renew/replace SSL certificate

 

In the production and home lab environments, the SSL Certificate is a point of attention that is especially important when the certificate is nearing its expiration date.

Normally, the expiration date is important to note in an Outlook calendar or other tool as a reminder to renew (a few days before, because if a Public CA generates the certificate, the renew requires waiting some days to have the certificate file). It is important to renew the certificate because some applications can stop running, and for the visibility of our business, it may have a bad reputation.

 

A screenshot of a computer error

Description automatically generated

Well in my home lab, where I use the NSX Advanced Load Balancer for Omnissa Horizon, at this time (Christmas Day) my wildcard SSL expired.

Well, I use a Let’s Encrypted certificate (free certificate) and I use Cerbot tool for the renewal.

On my PC where I installed the Cerbot tool I use this command to renew and create the certificate file:

certbot certonly –manual -d *.pollaio.site -d pollaio.site –agree-tos –preferred-challenges dns –server https://acme-v02.api.letsencrypt.org/directory –key-type rsa

A screenshot of a computer program

Description automatically generated

and I need to add a new TXT record on my DNS provider.

After adding the TXT record I can continue

A computer screen with white text

Description automatically generated

Now I have in my Cerbot directory this new file:

A screenshot of a computer

Description automatically generated

Well, I will use the cer9.pem, chain9.pem and privkey9.pem for the certificate renewal on NSX ALB.

Access NSX ALB console, go to templates zone and under Security select SSL/TLS Certificates

A screenshot of a computer

Description automatically generated

We need to add the new certificate, I suggest to create a new entry and not replace the actual certificate.

Under Create select Application Certificate

A screenshot of a computer

Description automatically generated

Add the certificate name (I normally add the name and the expiration date or the creation date) and how certificate type select Import

A screenshot of a certificate

Description automatically generated

In the first import select the certificate file, in the second import the private key.

Validate and Save the change.

Now in to the certificate list we have the new SSL certificate

If the certificate has an orange warning it is probably because we don’t have the full certificate chain and we need to load the root and sub ca on NSX ALB.

In the same console page where we show the uploaded SSL certificate we have at the bottom a section where we see the Root and Sub CA and we don’t watch the R10

A screenshot of a computer

Description automatically generated

Ok, no problem we have the chain9.pem file …

A screenshot of a computer

Description automatically generated

Select Create the root/intermediate CA Certificate

A screenshot of a computer

Description automatically generated

and import the pem chain file, Validate and Save

A screenshot of a computer

Description automatically generated

Now the row with the new certificate doesn’t show any warning or error

Now we are ready to replace the SSL certificate on Virtual Service.

Go to Application Menu, Virtual Service and edit the VS where we want to change the SSL certificate

A screenshot of a computer

Description automatically generated

On the bottom select the correct certificate form menu and remove the old certificate, after Save the change.

A screenshot of a computer

Description automatically generated

Now the SSL certificate is validated and I can connect to my VDI

A screenshot of a login screen

Description automatically generated

NSX Advanced Load Balancer renew/replace SSL certificate

Leave a Reply

Your email address will not be published. Required fields are marked *