Integration fails to import endpoint certificates in vRealize Log Insight 8.0
search cancel

Integration fails to import endpoint certificates in vRealize Log Insight 8.0

book

Article ID: 315929

calendar_today

Updated On:

Products

VMware Aria Suite

Issue/Introduction

Symptoms:
  • Integration with vRealize Operations, vCenter, Active Directory, SMTP or forwarding configurations using SSL is successful, but testing the connection prompts to accept the certificate again.
  • VIDM integration shows as disconnected on one or more nodes


Environment

VMware vRealize Log Insight 8.x

Cause

This issue is caused by the certificate failing to propagate across all vRealize Log Insight nodes.

Resolution

This issue is resolved in vRealize Log Insight 8.1 and later.
To resolve this issue, update to vRealize Log Insight 8.1 or later, available at Broadcom Portal.

Workaround:
To workaround this issue, copy the trust store from the Primary node to the other nodes in the vRealize Log Insight cluster.

  1. Log into the vRealize Log Insight UI using the direct address of the Primary node.
Examplehttps://192.168.4.10/login
  1. Test the connection and accept the certificate for any SSL configured integrations such as vSphere, vRealize Operations, SMTP, Active Directory, and/or Forwarder nodes.
  2. Using an SCP Utility as the root user, copy the /usr/java/jre-vmware/lib/security/cacerts file from the vRealize Log Insight Primary node to the /usr/java/jre-vmware/lib/security/ directory of all other nodes in the vRealize Log Insight cluster.
Example: scp root@healthynode:/usr/java/jre-vmware/lib/security/cacerts /usr/java/jre-vmware/lib/security/
 
Note: Enter your healthy node's IP or Fully Qualified Domain name (FQDN) in place of healthynode above.