Symptom 1:
The following error is seen while renewing the Aria Automation certificates or while trying to perform Day 2 actions ( such as Snapshots )
Error Code: LCMVRAVACONFIG590003
Cluster initialization failed on VMware Aria Automation.
com.vmware.vrealize.lcm.common.exception.EngineException: VMware Aria Automation Initialize cluster failed after certificate install.at com.vmware.vrealize.lcm.plugin.core.vra80.task.VraVaInstallCertificateTask.execute(VraVaInstallCertificateTask.java:175)at com.vmware.vrealize.lcm.automata.core.TaskThread.run(TaskThread.java:62)at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source)at java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source)at java.base/java.lang.Thread.run(Unknown Source)
Symptom 2:
HA environment contains 3 nodes.
HA deployment fails on initialization step (stage 9) with the following error:
Cause 1
The Aria Automation certificate renewal fails with LCMVRAVACONFIG590003
error because the identity-service-app pod does not initialize due to expired vIDM certificates.
This can be confirmed in the deploy.log file with the event "[2025-04-16 03:59:13] ERROR Release 'identity-service' in namespace 'prelude' failed to come up"
.
Cause 2
Solution for Symptom 1:
To check the vIDM certificate's expiration date in Chrome, navigate to the vIDM ui using the LB FQDN, click on the padlock icon (Not Secure) in the address bar, then click on "Certificate is Not Valid" and verify that the "Validity Period" section displays the expiration date.
Renew the vIDM certificates using the steps in the following KB Certificate Replacement for VMware Identity Manager deployed from Aria Suite Lifecycle.
Then resubmit the failed Aria Automation certificate failure request to continue with the certificate renewal, and this time the Aria Automation certificate should be renewed successfully.
Solution for Symptom 2:
SSH to the primary node.
Scale down vco-app deployment to zero pods:
\q