Resetting Expired Certificate to Default Self-Signed Certificate in VMware Identity Manager.
search cancel

Resetting Expired Certificate to Default Self-Signed Certificate in VMware Identity Manager.

book

Article ID: 429133

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

This article explains the procedure to restore administrative access to the VMware Identity Manager appliance when the SSL certificate has expired and the administrative portal is inaccessible.

Environment

VMware Identity Manager 3.3.7

Cause

The SSL certificate bound to the vIDM appliance has expired, preventing the HTTPS connector from initializing and rendering the administrative configuration page unreachable.

Resolution

Use the following steps to reset the certificate to the default self-signed state to regain access.

  1. Access the vIDM configuration page: https://<vIDM-FQDN>:8443/cfg
  2. Log in with the administrative credentials.
  3. Navigate to Install SSL Certificate > Server Certificate > SSL Certificate.
  4. Select Auto Generate Certificate (Self-Signed).
  5. Enter the vIDM FQDN in the Subject Alternative Names (SAN) field and click Save.
  6. In a clustered environment, repeat steps 1–5 on all vIDM nodes.
  7. Restart the horizon-workspace service to apply the configuration.

This process will restore certificate validity and bring the cluster services back online.
After functionality is restored, it is recommended to replace self-signed certificate with a valid CA-signed certificate per the organization's security policy.

Additional Information

For guidance on replacing self-signed certificates with custom CA-signed certificates, refer to the Adding or Replacing Certificates for VMware Identity Manager in Aria Suite Lifecycle