Aria Automation Identity services fails to start after certificate replacement in VMware Identity Manager.
search cancel

Aria Automation Identity services fails to start after certificate replacement in VMware Identity Manager.

book

Article ID: 406987

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

After replacing certificates of VMware Identity Manager, Identity service of Aria Automation get affected and pods remains in 0/1 status during initialize or running /opt/scripts/deploy.sh

  • kubectl get pods -n prelude | grep identity-service-app displays
    identity-service-app  0/1
  • /services-logs/prelude/identity-service-app/file-logs/identity-service-app.log logs exception CertPathValidatorException failure while connecting to VMware Identity Manager.

    PKIX path validation failed: java. security. cert. CertPathValidatorException: Path does not chain with any of the trust anchors

Environment

Aria Automation 8.x
VMware Identity Manager 3.3.x

Cause

This occurs due to a broken trust relationship or certificate mismatch between the Aria Automation and the VMware Identity Manager.

Resolution

Perform a re-trust operation through the lifecycle manager:

  1. Log in to Aria Suite Lifecycle.
  2. Navigate to Environments > Aria Automation.
  3. Trigger "Re-trust with VMware Identity Manager".

Note: This resolution holds true for situations where no VMware Identity Manager certificates were replaced but the trust is broken between Aria Automation and VMware Identity Manager.

Additional Information

This is one of the required steps while replacing certificates of VMware Identity Manager.
Certificate Replacement for VMware Identity Manager deployed from Aria Suite Lifecycle