Workspace ONE Access in Disconnected state in Aria Operations for Logs and fails to import certificate
search cancel

Workspace ONE Access in Disconnected state in Aria Operations for Logs and fails to import certificate

book

Article ID: 450256

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

Workspace ONE Access (vIDM) integration within Aria Operations for Logs shows a DISCONNECTED state. Attempts to import or update certificates fail, and the certificate UI appears empty despite successful uploads in other environments.

Symptoms:

  • Testing the vIDM connection triggers an infinite loop of certificate acceptance pop-ups.
  • Navigating to Management > Certificates shows no certificates listed.
  • Manual certificate addition does not list the new certificate in the UI.
  • Users receive the error Failed to receive user information by provided web-code during login.
  • The /storage/core/loginsight/runtime.log contains the following error:
Unable to get certificate with alias ####. Failed to add certificate to CA certs table.

Environment

  • Aria Operations for Logs 8.x
  • VMware Identity Manager 3.3.7

Cause

This issue typically occurs due to a stale service state within the Aria Operations for Logs appliance, often associated with long uptimes (e.g., 3+ months), which prevents the application from writing to the CA certificates table. Additionally, underlying health issues in the Workspace ONE Access environment (such as OpenSearch cluster failures or directory sync errors) can prevent the integration from reaching a Connected state even if certificates are accepted.

Resolution

  1. Reboot the Aria Operations for Logs appliance(s) to clear stale service states and restore write access to the certificate trust store.
  2. Once the appliance is back online, navigate to Integrations > VMware Identity Manager.
  3. Re-enter the integration credentials and click Test Connection.
  4. Click Accept when prompted for the certificate, then click Save.
  5. Verify the Workspace ONE Access health if authentication still fails:
    • Check the Workspace ONE Access UI for OpenSearch cluster status (must not be RED).
    • Ensure Directory Synchronization is successful and not showing errors.

Additional Information

Troubleshooting OpenSearch Cluster Health in VMware Identity Manager

Restart the VMware Aria Operations for Logs Service