Unable to locate or generate private keys for new certificates for VMware Identity Manager and the Load Balancer using VMware Aria Suite Lifecycle(LCM)
When creating a new certificate or importing a CA signed from LCM to replace expiring certificates, users are unable to import it into NSX Manager because the LCM locker only displays the SHA-1 fingerprint and does not show the private keys in the interface.
This is a known user experience limitation where the private key is not displayed directly in the LCM locker UI, but is instead embedded within the generated certificate file.
To locate the private key and resolve the issue, follow these steps:
Download the newly generated certificate PEM file from LCM.
Open the downloaded PEM file; the private key is located at the bottom of the file.
Verify that all VMware Identity Manager nodes and the Load Balancer FQDN are present in the certificate.
Follow the steps outlined in Adding or Replacing Certificates for VMware Identity Manager in Aria Suite Lifecycle to replace the certificate.