Aria Automation and Orchestrator Connection Issues After vCenter Certificate Update
search cancel

Aria Automation and Orchestrator Connection Issues After vCenter Certificate Update

book

Article ID: 409222

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

  • After upgrading a vCenter Server, the vCenter instance in Aria Orchestrator shows a status of unusable.
  • Workflows targeting the vCenter fail with the error: java.lang.reflect.InvocationTargetException.
  • Scripting methods such as getAllVMsMatchingRegexp or sdkConnection.allVms return null.
  • The Orchestrator logs show SSL handshake or thumbprint verification failures.

Environment

  • VMware Aria Automation
  • VMware Aria Orchestrator
  • vCenter Server 7.x / 8.x

Cause

Upgrading a vCenter Server often results in a new SSL certificate. Aria Orchestrator stores the certificate thumbprint of the vCenter instance when it is first added. If the thumbprint changes during an upgrade, Orchestrator rejects the connection, resulting in an InvocationTargetException and a null response for inventory lookups.

Resolution

Update the trust store in both Aria Automation and Aria Orchestrator for the new vCenter certificate.

A. For Aria Automation Cloud Account:

  1. Log in to Aria Automation as an administrator.
  2. Navigate to Infrastructure > Cloud Accounts.
  3. Locate and select the vCenter Cloud Account that is showing issues.
  4. Click the Edit button (pencil icon).
  5. In the Cloud Account configuration window, re-enter the password for the vCenter connection.
  6. Click the Validate button.
  7. A certificate warning dialog will appear, indicating that the certificate has changed. Review the certificate details and click ACCEPT or YES to import the new certificate into Aria Automation's trust store.
  8. Click SAVE to apply the changes to the Cloud Account.
  9. If this doesn't resolve the cloud account.  Use steps in this KB318756 to update the cloud account with the new certificate.

B. For Aria Orchestrator vCenter Endpoint:

  1. Log in to the Aria Orchestrator Client.
  2. Navigate to Library > Workflows.
  3. Search for the workflow: Update a vCenter Server instance.
  4. Run the workflow and select the affected vCenter Server instance.
  5. Review the new SSL certificate details when prompted and select Yes to accept the certificate and update the thumbprint.
  6. Verify the vCenter Server status returns to Available in the Inventory tab.

For further information on managing certificates, see VMware Aria Orchestrator Documentation.

If the issue persists, contact Broadcom Support. See Contact Broadcom Support.