Update VMware Products to trust vIDM after certificate replacement.
search cancel

Update VMware Products to trust vIDM after certificate replacement.

book

Article ID: 447771

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

  • Unable to used vIDM as authentication source post vIDM certificate replacement.
  • Attempting to login to Aria Automation prompted error "No Healthy Upstream"
  • Unable to login to Aria Suite Lifecycle using vIDM as auth provider, Error "{"code":401, "description":"Full authentication- is required to access this resource"}"
  • Error when logging into NSX portal using vIDM as auth provider, "Workspace ONE Access" (formerly known as VIDM) is not accessible. CLICK HERE to log in to NSX Manager using your local user account."

Environment

  • VMware Identity Manager 3.3.7
  • Aria Automation 8.18.x
  • Aria Operation 8.18.x
  • Aria Operations for logs 8.18.x
  • Aria Suite Lifecycle 8.18
  • VMware NSX 4.x
  • VCF Automation 9.x

Cause

  • The products were not synced with the latest vIDM certificate post replacement, thus making the authentication provider configurations invalid. 
  • With the products using the older / invalid certificates to establish connection to vIDM, failed to secure a valid connection / auth token for further communication / authentication, thus failing to login. 
  • The thumbprint / certificate chain held by the products were invalid and did not match the one of the presently valid certificate.

Resolution

  • Ensuring that all products using the vIDM as the authentication provider have trusted the new certificate of viDM, would ensure seamless authentications post cert replacement. 

    Aria Automation
    • Re-Trust / Re-Register vIDM to Aria Automation as per Step 4 : KB372708
    Aria Operations
    • Re-trust the vIDM certificate on the Aria Operations Authentication source configuration : KB394123
    Aria Operations for logs
    • Log in to Aria Suite Lifecycle UI
    • Navigate to Lifecycle Operations > Manage Environments
    • Click 'View Details' on the Operations for Logs environment.
    • Click on the three horizontal dots beside the 'Upgrade' option on the middle title bar.
    • Click 'Re-trust With Identity Manager'
    Aria Suite Lifecycle
    • Re-register vIDM as an authentication provider on Aria Suite Lifecycle as per: KB322701
    VMware NSX
    • Update vIDM SSL Thumbprint on NSX as per : KB381832
    VCF Automation 9.0.x
    • VCFA 9.0.x : (Re-trust using script: KB410075
    • VCFA 9.0.x : (Re-trust using APIs / UI) : KB437529