Aria Automation Orchestrator integration fails with error LCMVROVACONFIG100034 in Aria Suite Lifecycle Manager
search cancel

Aria Automation Orchestrator integration fails with error LCMVROVACONFIG100034 in Aria Suite Lifecycle Manager

book

Article ID: 427647

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

When adding a new VMware Aria Automation Orchestrator server to a VMware Aria Automation tenant, the task fails during the authentication configuration phase. In VMware Aria Suite Lifecycle Manager, the request fails with the following error:

LCMVROVACONFIG100034

When reviewing the log file /var/log/vrlcm/vmware_vrlcm.log, you may observe that the system is unable to fetch the SSL certificate from the Aria Automation tenant URL:

2026-01-28T16:21:07.089Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.d.v.h.VroUtil]  -- vRO ENDPOINT HOST :: tenant-orchestrator.example.com
2026-01-28T16:21:07.089Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.d.v.h.VroUtil]  -- COMMAND :: vracli vro authentication set -p vra -hn tenant-automation.example.com -u configadmin --password-file YXYXYXYX -f -k
2026-01-28T16:21:07.151Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.u.SshUtils]  -- Executing command on the host: tenant-orchestrator.example.com , as user: root
2026-01-28T16:21:07.151Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.u.SshUtils]  -- ------------------------------------------------------
2026-01-28T16:21:07.151Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.u.SshUtils]  -- Command: vracli vro authentication set -p vra -hn tenant-automation.example.com -u configadmin --password-file YXYXYXYX -f -k
2026-01-28T16:21:07.151Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.u.SshUtils]  -- ------------------------------------------------------
2026-01-28T16:21:24.594Z INFO vrlcm[####] [http-nio-8080-exec-6] [c.v.v.l.s.n.s.NotificationServiceImpl]  -- Authentication object is not null org.springframework.security.authentication.UsernamePasswordAuthenticationToken@fe908ae6: YXY
XYXYX org.springframework.security.core.userdetails.User@c220133a: Username: admin@local; Password: YXYXYXYX Enabled: true; AccountNonExpired: true; credentialsNonExpired: true; AccountNonLocked: true; Granted Authorities: LCM_ADMIN; Credentials: [PROTECTED]; Authenticated: true; Details: org.springframework.security.web.authentication.WebAuthenticationDetails@957e: RemoteIpAddress: 127.0.0.1; SessionId: null; Granted Authorities: LCM_ADMIN
2026-01-28T16:21:37.201Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.u.SshUtils]  -- exit-status: 255
2026-01-28T16:21:37.201Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.u.SshUtils]  -- Command executed sucessfully
2026-01-28T16:21:37.201Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.d.v.h.VroUtil]  -- Command Status code :: 255
2026-01-28T16:21:37.201Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.d.v.h.VroUtil]  -- ====================================================
2026-01-28T16:21:37.201Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.d.v.h.VroUtil]  -- Output Stream ::
2026-01-28T16:21:37.201Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.d.v.h.VroUtil]  -- ====================================================
2026-01-28T16:21:37.201Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.d.v.h.VroUtil]  -- Could not an SSL fetch certificate from URL: tenant-automation.example.com
pod prelude/vro-cli-###### terminated (Error)

2026-01-28T16:21:37.201Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.d.v.h.VroUtil]  -- ====================================================
2026-01-28T16:21:37.201Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.d.v.h.VroUtil]  -- Error Stream ::
2026-01-28T16:21:37.201Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.d.v.h.VroUtil]  -- ====================================================
2026-01-28T16:21:37.201Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.d.v.h.VroUtil]  -- null
2026-01-28T16:21:37.201Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.d.v.h.VroUtil]  -- ====================================================
2026-01-28T16:21:37.201Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.d.v.t.SetNewVroVraAuthConfigTask]  -- VMware Aria Automation Orchestrator integration SSH response: {
  "exitStatus" : 255,
  "outputData" : "Could not an SSL fetch certificate from URL: tenant-automation.example.com\npod prelude/vro-cli-###### terminated (Error)\n",
  "errorData" : null,
  "commandTimedOut" : false
}
2026-01-28T16:21:37.201Z ERROR vrlcm[####] [pool-#thread-##] [c.v.v.l.d.v.t.SetNewVroVraAuthConfigTask]  -- VMware Aria Automation Authentication Unsuccessful.
2026-01-28T16:21:37.201Z INFO vrlcm[####] [pool-#thread-##] [c.v.v.l.p.a.s.Task]  -- Injecting task failure event. Error Code : 'LCMVROVACONFIG100034', Retry : 'true', Causing Properties : '{ CAUSE :: rootPassword YXYXYXYX  }'
com.vmware.vrealize.lcm.driver.vro.domain.common.exception.VroVraAuthenticationException: Error in setting the VMware Aria Automation as authentication provider in VMware Aria Automation Orchestrator
        at com.vmware.vrealize.lcm.drivers.vro.task.SetNewVroVraAuthConfigTask.execute(SetNewVroVraAuthConfigTask.java:133) [vmlcm-vroplugin-core-8.18.0-SNAPSHOT.jar!/:?]
        at com.vmware.vrealize.lcm.automata.core.TaskThread.run(TaskThread.java:62) [vmlcm-engineservice-core-8.18.0-SNAPSHOT.jar!/:?]
        at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(Unknown Source) [?:?]
        at java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run(Unknown Source) [?:?]
        at java.base/java.lang.Thread.run(Unknown Source) [?:?]
2026-01-28T16:21:38.696Z INFO vrlcm[####] [scheduling-1] [c.v.v.l.r.c.RequestProcessor]  -- Updating the Environment request status to FAILED for environment : ENVIRONMENTNAME with request ID : ########-####-####-####-############ and request type : ADD_PRODUCT.
 

Environment

  • VMware Aria Suite Lifecycle Manager

  • VMware Aria Automation

  • VMware Aria Automation Orchestrator

Cause

The integration fails because the Orchestrator server cannot establish a network connection to the Aria Automation tenant's Load Balancer. This prevents the Orchestrator server from retrieving the necessary SSL certificate required to complete the authentication configuration.

Resolution

To resolve this issue, you must ensure that the necessary network ports are open between the new Orchestrator server and the Aria Automation Load Balancer.

  1. Log in to the Orchestrator server's command line via SSH.

  2. Verify the connection to the Aria Automation tenant on port 443 using the following command: curl -kv telnet://<tenant-automation-fqdn>:443

  3. Alternatively, attempt to manually fetch the certificate: openssl s_client -connect <tenant-automation-fqdn>:443 -showcerts

  4. If the connection fails or times out, work with your network team to unblock traffic between the Orchestrator server and the Aria Automation Load Balancer.

  5. Once connectivity is restored, return to VMware Aria Suite Lifecycle Manager and retry the failed task.