'Certificate validation failed' warning message for adapter in Aria Operations
search cancel

'Certificate validation failed' warning message for adapter in Aria Operations

book

Article ID: 312234

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

  • Adapter is in warning state with message Certificate validation failed when mousing over warning for adapter instance:
    State: Collecting
    Status: Object Down
    Message: Certificate validation failed
  • When generating a report for objects that are collected by the affected adapter instance the metrics will appear with - (hyphen) due to missing data collection
  • A global banner appears in the UI: "Your certificate is expired. Please check the expiry date to take an action."

Environment

Aria Operations 8.x

Cause

The adapter collection stops because the Aria Operations trust store contains an expired or mismatched certificate for the endpoint. This commonly occurs after a certificate rotation on the adapter instance endpoint that was not subsequently validated in the Aria Operations integrations menu.

Resolution

  1. Verify that the certificate on the endpoint is not expired before proceeding. Renew certificate on endpoint if required, by following vendor documentation for replacing certificate on endpoint
  2. Log in to the VMware Aria Operations UI as an administrator.
  3. Navigate to Administration > Control Panel > Trusted Certificates (For Aria Operations versions below 8.18 navigate to Administration > Certificates). 
  4. Locate the certificate for affected adapter instance that is not collecting
  5. Delete the certificate 
  6. Navigate to Administration > Integrations (or Data Sources > Integrations in older versions).
  7. Select the affected adapter instance and click Edit.
  8. Click Validate Connection.
  9. When the certificate window appears, click OK to accept and trust the new certificate.
  10. Click Save.
  11. Navigate to Operations > Configurations > Inventory Management > Adapter Instances.
  12. Select the adapter, click Stop Collection, and then click Start Collection to refresh the cycle.

Additional Information

For detailed steps on clearing the expired certificate banner from the truststore, see Aria Operations adapter certificate renewal and Expired Certificates banner cleanup

Review article Certificate overview for VMware Aria Operations section 'Adapter and authentication sources' for more information on endpoint certificates and potential caveats.