After replacing the Infoblox endpoint certificate, workflows in Aria Automation Orchestrator fail with SSL certificate errors
search cancel

After replacing the Infoblox endpoint certificate, workflows in Aria Automation Orchestrator fail with SSL certificate errors

book

Article ID: 398288

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

  • Running the "Create IPAM connection" workflow or attempts to connect to the plugins cache of endpoints during a custom workflow execution fail with an SSL certificate error.

    WARNING An error has occurred while checking connection with Infoblox IPAM server. Detail: SSL certificate error. (Workflow:Create IPAM connection / isConnectionOnline (item12)#4)

  • You are using an outdated IPAM Plug-In for VMware Aria Automation Orchestrator version such as version 4.4.x.
  • When reviewing the Orchestrator certificate trust store, you see the correct Infoblox client certificate, intermediate certificate, and root certificate that has signed the Infoblox client certificate.
  • You may have recently replaced the Infoblox certificate.

Environment

VMware Aria Automation Orchestrator 8.18.x

Cause

Infoblox's Orchestrator plugin uses an internal caching mechanism for endpoints created through the Create IPAM connection workflow. You must run this workflow to create a validate connection after any Infoblox endpoint certificate updates.

It is recommended to use the plugin version where it is stated to provide support for later version of Orchestrator.

  • Note: IPAM Plug-In for VMware Aria Automation Orchestrator 6.1.0 and above provides official support for Aria Automation Orchestrator 8.17 and above, with 6.3.0 being the latest release at the time of this articles publication.

Resolution

  1. Download version 6.3.0 of the Infoblox IPAM plugin for Aria Automation Orchestrator.
  2. Extract the *.dar file and import it into Orchestrator > System Settings > Plugins > Add a plugin.
  3. Orchestrator services will automatically restart. Allow for this to complete.
  4. Rerun the Create IPAM connection workflow using the appropriate service account credentials. This should complete without errors.
  5. Retest your custom workflow that uses this Infoblox endpoint.