Tunnel client missing in IM with "Could not read private key file" error after certificate renewal
search cancel

Tunnel client missing in IM with "Could not read private key file" error after certificate renewal

book

Article ID: 450330

calendar_today

Updated On:

Products

DX Unified Infrastructure Management (Nimsoft / UIM)

Issue/Introduction

After deploying new tunnel certificates in DX Unified Infrastructure Management (UIM), the tunnel client hub no longer appears in Infrastructure Manager (IM) or Admin Console.

  1. Launch IM and logging in directly to the IP of the missing Tunnel Hub
  2.  In the hub configuration under the Status > Tunnel Status tab, the connection to the Tunnel server is shown in a failed state (Red).
  3. Hovering the mouse over the failed hub entry reveals the following message: "Password error: Invalid or missing certificate password. Reason: failed to decrypt certificate"
  4. The hub.logon the affected client hub shows:
    • ssl_log_error - Could not read private key file.
    • [1] error:0x80000002: system library: func(2147483650): reason(2)

Environment

  • DX UIM (Any Version)
  • Hub probe (23.4 or later)

Resolution

To resolve this, you must update the certificate password on the affected client hub:

  1. Access the Client Hub:

    • Open Infrastructure Manager (IM).
    • Go to Security > Login.
    • Click Advanced and enter the IP address of the missing client hub to log in directly.
  2. Navigate to Tunnel Settings:

    • Locate the hub probe on the client robot.
    • Right-click and select Configure.
    • Navigate to the Tunnels tab and then the Client Configuration sub-tab.
  3. Update the Password:

    • Select the tunnel connection entry for the server and click Edit.
    • In the Password field, re-enter the exact password that was used when the new certificate was generated on the Tunnel Server.
    • If the certificate text itself was not updated yet, ensure you have also pasted the new certificate content into the Certificate text area.
  4. Restart and Verify:

    • Click OK and then Apply. The hub will restart to apply the new configuration.
    • Once the hub restarts, verify the Status > Tunnel Status tab
    • The hub should now be visible in the main Infrastructure Manager navigation tree.