Deployment of VMware Identity Manager from Aria Suite Lifecycle Manager is failing during the precheck stage with a “Firewall check on all hosts” error caused by data validation issues.
search cancel

Deployment of VMware Identity Manager from Aria Suite Lifecycle Manager is failing during the precheck stage with a “Firewall check on all hosts” error caused by data validation issues.

book

Article ID: 413540

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

  • Navigating to Aria Suite Lifecycle UI > Create Environment, the precheck fails at the step “Firewall check on all the hosts”, referencing the datacenter and cluster name.

  • The /var/log/vrlcm/vmware-vrlcm.log shows below error related to certificate "Certificate doesn't support 'digitalSignature' KeyUsage"

2025-10-07T10:30:25.788Z ERROR vrlcm[1309] [pool-3-thread-37] [c.v.v.l.d.c.v.i.ClusterValidator]  -- Exception occurred while validating esx hosts connection from VMware Aria Suite Lifecycle VA
org.bouncycastle.tls.TlsFatalAlert: certificate_unknown(46)
        at org.bouncycastle.jsse.provider.ProvSSLSocketDirect.checkServerTrusted(ProvSSLSocketDirect.java:134) ~[bctls-jdk15on-1.65.jar:1.65.00.0]
        at org.bouncycastle.jsse.provider.ProvTlsClient$1.notifyServerCertificate(ProvTlsClient.java:251) ~[bctls-jdk15on-1.65.jar:1.65.00.0]
        
Caused by: java.security.cert.CertificateException: Certificates do not conform to algorithm constraints

        at org.bouncycastle.jsse.provider.ImportX509TrustManager_5.checkAlgorithmConstraints(ImportX509TrustManager_5.java:107) ~[bctls-jdk15on-1.65.jar:1.65.00.0]
        at org.bouncycastle.jsse.provider.ImportX509TrustManager_5.checkAdditionalTrust(ImportX509TrustManager_5.java:87) ~[bctls-jdk15on-1.65.jar:1.65.00.0]
Caused by: java.security.cert.CertPathValidatorException: Certificate doesn't support 'digitalSignature' KeyUsage
        at org.bouncycastle.jsse.provider.ProvAlgorithmChecker.checkEndEntity(ProvAlgorithmChecker.java:200) ~[bctls-jdk15on-1.65.jar:1.65.00.0]
        at org.bouncycastle.jsse.provider.ProvAlgorithmChecker.checkChain(ProvAlgorithmChecker.java:180) ~[bctls-jdk15on-1.65.jar:1.65.00.0]

  • The certificate on ESXi hosts does not show digitalSignature parameter in key usage of certificate field.

Environment

Aria Suite Lifecycle Manager 8.18

VMware Identity Manager 3.3.7

Cause

The ESXi host certificate does not contain the ‘digitalSignature’ parameter in the KeyUsage section of certificate.

Resolution

To resolve this issue, please follow the steps outlined in the KB article below:

Add the ‘digitalSignature’ parameter in the KeyUsage section of the certificate.

For detailed instructions, refer to the following KB:

https://knowledge.broadcom.com/external/article/400932/importing-the-ovf-package-fails-with-the.html