Vulnerability Scanner Flags SSL Certificate as Untrusted or Self-Signed in VMware Aria Suite Lifecycle
search cancel

Vulnerability Scanner Flags SSL Certificate as Untrusted or Self-Signed in VMware Aria Suite Lifecycle

book

Article ID: 456266

calendar_today

Updated On:

Products

VCF Operations/Automation (formerly VMware Aria Suite)

Issue/Introduction

Security vulnerability scanners flag the VMware Aria Suite Lifecycle appliance with warnings similar to the following:

  • SSL Certificate Cannot Be Trusted: "The following certificate was at the top of the certificate chain sent by the remote host, but it is signed by an unknown certificate authority... The SSL certificate for this service cannot be trusted."

  • SSL Self-Signed Certificate: "The following certificate was found at the top of the certificate chain sent by the remote host, but is self-signed and was not found in the list of known certificate authorities... The SSL certificate chain for this service ends in an unrecognized self-signed certificate."

Environment

VMware Aria Suite Lifecycle 8.18.x

Cause

VMware Aria Suite Lifecycle appliance is deployed with a self-signed SSL certificate. Security vulnerability scanners flag self-signed certificates as untrusted.

Resolution

Resolution To permanently resolve this vulnerability, replace the default self-signed certificate with a custom Certificate Authority (CA) signed certificate trusted by your organization. This can be accomplished using Aria Suite Lifecycle's built-in Locker service.

Steps:

  1. Log in to the VMware Aria Suite Lifecycle appliance UI.

  2. Navigate to Lifecycle Operations > Locker > Certificate.

  3. Generate a new Certificate Signing Request (CSR) and have it signed by your internal or third-party CA.

  4. Import the newly signed certificate chain (including the Root, Intermediate, and Server certificates) back into the Locker.

  5. Navigate to Lifecycle Operations > Settings > Change Certificate.

  6. Click Replace Certificate and select your newly imported CA-signed certificate to apply it to the appliance.

Reference