Configuring Licensing Hub to use a HTTP TLS inspecting MITM Web Proxy failed with "failed to verify certificate: x509 certificate signed by unknown authority" is the proxy is configured to reissue certificate using non-public CA certificate.
Licensing Hub 2.0
Licensing Hub 2.0 currently does not support connecting to Pulse over HTTP TLS inspecting MITM web proxy.
Note- After upgrade changes made would be lost, if you are upgrading from LH 2.0 to any other version, please contact Broadcom support as the workaround in this KB is only designed to work with LH 2.0. If there is a need to perform DR restore, users need to re-apply the script.
Easiest resolution is to switch to use LH as airgapped setup and download the license bundle out-of-band.
Reference Document- Register and Assign License Using Disconnected Mode
If that's not desired or not feasible. The following workaround can be applied.
Step 1.
- Import the CA TLS-Inspecting proxy uses to re-sign external certificates as a CABundle using LH UI. Note that this should only contain THE CA used by the proxy to resign certificates on the fly and not a big bundle of public CAs + the signing CA. To be precise, please name this CA Bundle as "mitm-ca".
Reference Document- Import CA Bundles to License Hub
Step 2.
- Download the attached "patch-lh-mitm-trust.sh" bash script and copy the script over to licensing hub root folder using scp.
- SSH to license hub as sysadmin user.
- Run the script and wait for cluster-api and licensing-service pods to restart. Once they have restarted successfully, you can proceed to the UI to configure the web proxy.
bash patch-lh-mitm-trust.shCheck the status of the pods as stated above-
kubectl get pods -n nsxi-platform | grep "cluster-api"
kubectl get pods -n nsxi-platform | grep "licensing-service"
When it's time to renew the MITM signing CA, simply go to UI and update the CA bundle with the "mitm-ca" name with the new certificate and the system would pick up the new CA automatically.