As organizations continue to strengthen their security posture and simplify operational management, platform security has become a critical pillar of modern cloud infrastructure. VMware Cloud Foundation (VCF) 9.1 introduces several important security-focused enhancements within NSX that improve certificate management, strengthen authentication controls, reduce attack surfaces, and modernize the underlying platform architecture.
In this fourth installment of our VCF 9.1 networking series, we'll explore the latest platform security improvements that help organizations build more resilient, secure, and manageable environments.
Non-Disruptive Certificate Renewal for NSX-Integrated VCF Components
Managing certificates across complex infrastructure platforms has traditionally been an operational challenge. Certificate renewals can potentially introduce service interruptions if dependent systems fail to immediately trust newly issued certificates.
To address this, VCF 9.1 introduces support for a standardized Non-Disruptive Certificate architecture across VCF components that consume NSX services.
Why This Matters
Many VMware Cloud Foundation services rely on secure communication with NSX. Previously, certificate changes could require additional validation activities to ensure platform components continued to trust NSX services.
With the new architecture, VCF components can maintain trust relationships with NSX even when NSX server certificates are renewed or replaced.
Key Benefits
- Reduced operational risk during certificate renewals
- Improved service continuity
- Simplified certificate lifecycle management
- Better alignment with enterprise security practices
- Reduced maintenance windows
For organizations operating large-scale environments, this enhancement significantly reduces the administrative burden associated with certificate management while improving overall platform stability.
Enhanced Backup Security with RSA and SSH-ED Algorithm Support
Backup and recovery systems are only as secure as the mechanisms used to protect them. Recognizing this, VCF 9.1 expands security capabilities for NSX Backup and Restore operations.
NSX Backup and Restore now supports:
- RSA host key algorithms
- SSH-ED host key algorithms
This enhancement provides greater flexibility when integrating NSX with enterprise backup repositories and aligns NSX backup functionality with modern security standards.
Benefits of Expanded Host Key Support
Organizations can now:
- Standardize backup security configurations
- Improve cryptographic consistency across infrastructure
- Meet internal compliance requirements
- Leverage stronger authentication mechanisms
Important Note
If you plan to use the ssh-ed25519 host key algorithm, backup configuration must be performed through the NSX Manager UI or API.
This requirement helps ensure proper implementation and compatibility when utilizing the more modern SSH-ED authentication method.
Stronger Password Controls for Local Accounts
Credential security remains one of the most fundamental components of any cybersecurity strategy.
Beginning with VCF 9.1, NSX enforces an additional safeguard during password reset operations for local accounts.
What's Changing?
When performing a password reset, users can no longer reuse their existing password.
The new password must be different from the old one.
Why This Is Important
While this may seem like a small change, it helps strengthen security by preventing ineffective password reset practices where users simply re-enter their current credentials.
Benefits include:
- Improved password hygiene
- Stronger account protection
- Better compliance with security policies
- Reduced risk of credential reuse
This enhancement aligns NSX with security best practices commonly found in enterprise identity and access management programs.
NSX Internal Operations No Longer Depend on Visible ESXi User Accounts
One of the more significant security architecture changes in VCF 9.1 involves how NSX performs operations on ESXi hosts.
Historically, NSX created several regular user accounts on ESXi hosts to facilitate various platform functions, including:
- mux_user
- da-user
- nsx-user
- lldpVim-user
Starting with VCF 9.1, these accounts are no longer created or used.
A Shift Toward Internal Service Accounts
Instead, NSX now leverages specialized internal accounts that are not exposed to users.
This architectural change delivers multiple advantages:
- Reduced attack surface
- Fewer visible privileged accounts
- Improved security posture
- Simplified user management
- Reduced administrative overhead
Security Benefits
By eliminating the need for these user-visible service accounts, organizations gain tighter control over host access while reducing the opportunities for misuse, misconfiguration, or unauthorized account discovery.
This change also helps security teams maintain a cleaner and more streamlined account landscape across ESXi environments.
NSX Moves to Ubuntu 24.04 and Chiseled Containers
Perhaps the most impactful platform modernization initiative in VCF 9.1 is the upgrade of all NSX appliances to Ubuntu 24.04.
This upgrade is more than a simple operating system refresh. It represents a broader strategy to improve security, maintainability, and deployment efficiency.
Modern Operating System Foundation
Ubuntu 24.04 provides:
- Long-term enterprise support
- Updated security frameworks
- Modern package libraries
- Ongoing vulnerability remediation
This ensures NSX appliances are built upon a contemporary and well-supported operating system platform.
Introducing Chiseled Containers
In addition to adopting Ubuntu 24.04, NSX now leverages chiseled containers.
Chiseled containers are designed to include only the components necessary for the application to function, removing unnecessary packages, binaries, and services.
Benefits of Chiseled Containers
Reduced Attack Surface
By eliminating unnecessary software components, there are fewer potential entry points available to attackers.
Improved Deployment Efficiency
Smaller container footprints typically result in:
- Faster deployment times
- Reduced resource consumption
- Simplified updates
Streamlined Patch Management
With fewer components to maintain, security patching becomes more straightforward and predictable.
Greater Operational Consistency
A unified and enterprise-supported software stack improves reliability across the platform and simplifies lifecycle management activities.
Final Thoughts
The security enhancements introduced in VMware Cloud Foundation 9.1 demonstrate a continued commitment to platform hardening, operational resilience, and modern infrastructure design.
From non-disruptive certificate management and enhanced backup security to stronger password controls and the removal of legacy service accounts, NSX is becoming both more secure and easier to manage.
The transition to Ubuntu 24.04 and chiseled containers is particularly significant, providing a modern and streamlined foundation that reduces attack surface while improving deployment and patch management efficiency.
Collectively, these improvements help organizations strengthen their security posture without increasing administrative overhead, ensuring that NSX remains a secure and resilient networking platform for today's private cloud and multi-cloud environments.
In the next installment of this series, we'll continue exploring additional innovations and enhancements introduced in VMware Cloud Foundation 9.1, helping you understand how the platform is evolving to meet modern networking, security, and operational demands.