Unable to update the VMware Aria Operations web certificate using VMware Aria Suite Lifecycle
search cancel

Unable to update the VMware Aria Operations web certificate using VMware Aria Suite Lifecycle

book

Article ID: 325751

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

The purpose of this article is to explain how to renew the web certificate in VMware Aria Operations and restore connectivity between VMware Aria Operations and VMware Aria Suite Lifecycle .

Symptoms:
  • Unable to apply/update the VMware Aria Operations web certificate using VMware Aria Suite Lifecycle due to the certificate having already expired. 
  • The VMware Aria Operations cluster is unable to go ONLINE due to the expired certificate.

Environment

VMware Aria Operations 8.16.x and Later

Cause

  • The connectivity between VMware Aria Suite Lifecycle and VMware Aria Operations stops working due to expired VMware Aria Operations web certificate
  • This prevents the Aria Suite Lifecycle appliance from renewing the VMware Aria Operations certificate via its certificate renewal workflow.

Resolution

Option 1 

  1. Take a snapshot of the VMware Aria Operations nodes as per KB Snapshot Creation in VMware Aria Operations 
  2. SSH to ALL of the VMware Aria Operations nodes and login as the root account.
  3. Reload the default web certificate as per the steps outlined in KB Reload the default certificate in Aria Operations.
    • unset -f pathprepend
    • unset -f pathremove
    • unset -f pathappend
    • $VMWARE_PYTHON_BIN /usr/lib/vmware-casa/bin/activate_web_certificate.py DEFAULT
    • $VMWARE_PYTHON_BIN /usr/lib/vmware-vcopssuite/utilities/bin/restartHttpd.py
    • Repeat the above steps on ALL nodes before continuing to step 4.
  4. Take the VMware Aria Operations cluster offline via the Admin UI.
  5. Bring the VMware Aria Operations cluster online via the Admin UI and wait for the cluster to come fully online.
  6. Trigger an inventory sync from VMware Aria Suite Lifecycle against the VMware Aria Operations environment and verify the inventory sync completes. You can use the following documentation as a guide Inventory synchronization in VMware Aria Suite Lifecycle .
  7. Generate a CSR certificate from VMware Aria Suite Lifecycle certificate page.  You can use the following documentation as a guide Manage certificates for VMware Aria Suite Lifecycle products 
  8. Download the newly generated certificate from the VMware Aria Suite Lifecycle certificate page by selecting 'Download' from the context menu.
  9. Take the VMware Aria Operations cluster offline via the Admin UI.
  10. Upload the new custom web certificate via the VMware Aria Operations Admin UI
    • This is done by logging in as the admin user and clicking the certificate icon in the top right hand corner and selecting 'INSTALL A NEW CERTIFICATE' then browsing to the certificate PEM file and uploading it.
  11. Bring the VMware Aria Operations cluster back online and wait for the cluster to come fully online.
  12. Trigger an inventory sync from VMware Aria Suite Lifecycle against the VMware Aria Operations environment and verify the inventory sync completes.
  13. Verify the certificate is listed as in use under the Aria Suite Lifecycle certificate page and view the listed environment and confirm it lists the VMware Aria Operations environment.

Option 2

  1. Take a snapshot of the VMware Aria Operations nodes as per KB Snapshot Creation in VMware Aria Operations .
  2. Reload the default web certificate as per the steps outlined in KB Reload the default certificate in Aria Operations .   
  3. Trigger inventory sync for the VMware Aria Operations environment . You can use the following documentation as a guide Inventory synchronization in VMware Aria Suite Lifecycle  
  4. Generate a new certificate in VMware Aria Suite Lifecycle UI.  You can use the following documentation as a guide Manage certificates for VMware Aria Suite Lifecycle products
    1. From the VMware Aria Suite Lifecycle My Services dashboard -> Click Locker -> Select Generate
    2. Use the expired certificate details to fill in the fields required for the new certificate
    3. Click Generate
  5. Replace the expired certificate that is currently assigned to the VMware Aria Operations Product card in the Environment page with the newly generated certificate that was generated following step 4 above.  You can use the following documentation as a guide to replacing the certificate Replace certificate for VMware Aria Suite Lifecycle products

Additional Information