Using HTTP with TLS inspecting Man-In-The-Middle Web Proxy Failed
search cancel

Using HTTP with TLS inspecting Man-In-The-Middle Web Proxy Failed

book

Article ID: 456236

calendar_today

Updated On:

Products

VMware vDefend Firewall VMware vDefend Firewall with Advanced Threat Prevention

Issue/Introduction

Configuring Licensing Hub to use a HTTP TLS inspecting MITM Web Proxy failed with "failed to verify certificate: x509 certificate signed by unknown authority" is the proxy is configured to reissue certificate using non-public CA certificate.

Environment

Licensing Hub 2.0

Cause

Licensing Hub 2.0 currently does not support connecting to Pulse over HTTP TLS inspecting MITM web proxy.

Resolution

Note- After upgrade changes made would be lost, if you are upgrading from LH 2.0 to any other version, please contact Broadcom support as the workaround in this KB is only designed to work with LH 2.0. If there is a need to perform DR restore, users need to re-apply the script.

 

Easiest resolution is to switch to use LH as airgapped setup and download the license bundle out-of-band.

Reference Document- Register and Assign License Using Disconnected Mode

 

If that's not desired or not feasible.  The following workaround can be applied.

Step 1.

- Import the CA TLS-Inspecting proxy uses to re-sign external certificates as a CABundle using LH UI.  Note that this should only contain THE CA used by the proxy to resign certificates on the fly and not a big bundle of public CAs + the signing CA.  To be precise, please name this CA Bundle as "mitm-ca".

Reference Document- Import CA Bundles to License Hub

 


Step 2.

- Download the attached "patch-lh-mitm-trust.sh" bash script and copy the script over to licensing hub root folder using scp. 

- SSH to license hub as sysadmin user.

- Run the script and wait for cluster-api and licensing-service pods to restart.  Once they have restarted successfully, you can proceed to the UI to configure the web proxy.

bash patch-lh-mitm-trust.sh
Check the status of the pods as stated above-

kubectl get pods -n nsxi-platform | grep "cluster-api"


kubectl get pods -n nsxi-platform | grep "licensing-service"

 

When it's time to renew the MITM signing CA, simply go to UI and update  the CA bundle with the "mitm-ca" name with the new certificate and the system would pick up the new CA automatically.

 

 

Attachments

patch-lh-mitm-trust.sh get_app