Login fails with SAML AuthnRequest issuer mismatch after certificate replacement in Aria Automation
search cancel

Login fails with SAML AuthnRequest issuer mismatch after certificate replacement in Aria Automation

book

Article ID: 449365

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

  • Users are unable to authenticate into the Aria Automation portal using domain credentials.
  • Login attempts fail with the error: Incorrect issuer in SAML AuthnRequest.
  • The issue often follows a certificate replacement, load balancer modification, or product upgrade.

Environment

  • VMware Identity Manager 3.3.7
  • VMware Aria Automation 8.18.x
  • VMware Aria Suite Lifecycle 8.18.x

Cause

Aria Automation integration becomes out of sync with the Workspace ONE Access (vIDM) cluster configuration. The service expects an authentication request from the load-balancer FQDN but due to difference in LB FQDNs in config-state.json the request fails.

Resolution

  1. Log in to the VMware Aria Suite Lifecycle UI.
  2. Navigate to Lifecycle Operations > Environments.
  3. Select the environment containing the impacted Aria Automation instance.
  4. Click on the Aria Automation tab.
  5. Select Triggered Request or Day 2 Operations.
  6. Select the operation Re-register with Identity Manager.
  7. Follow the wizard to complete the synchronization.
  8. Once the task completes successfully, verify that domain authentication is restored.

Additional Information

If the issue persists, Verify the LB url in all the config-state.json: Follow KB Error Incorrect issuer in SAML AuthnRequest.