Aria Orchestrator certificate replacement precheck fails from Aria Suite Lifecycle
search cancel

Aria Orchestrator certificate replacement precheck fails from Aria Suite Lifecycle

book

Article ID: 420444

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

Error message shows "The hosts in the certificate doesn't match with the provided/product hosts"

Environment

VMware Aria Suite Lifecycle 8.18.x
VMware Aria Orchestrator 8.18.1

Cause

Missing hostnames and IPs of Aria Orchestrator nodes on the SAN field of the certificate.

Resolution

1. Generate a new certificate using VMware Aria Suite Lifecycle.

https://techdocs.broadcom.com/us/en/vmware-cis/aria/aria-suite-lifecycle/8-18/vmware-aria-suite-lifecycle-installation-upgrade-and-management-8-18/configuring-vmware-aria-suite-lifecycle/manage-certificates.html

2. During generation of new certificate, add all hostnames and IPs recommended by the certificate replacement precheck to the certificate's Subject Alternative Name (SAN) fields. Alternatively, use a wildcard certificate to cover all the hostnames.