Validating Workspace One Access 3.3.x (formerly VMware Identity Manager) health
book
Article ID: 326087
calendar_today
Updated On:
Products
VMware Aria Suite
Issue/Introduction
This article provides a list of steps to validate the health for Workspace One Access 3.3.x (formerly VMware Identity Manager) used with the VMware Aria Suite products.
Environment
VMware Identity Manager 3.3.x VMware Aria Suite Lifecycle 8.x
Resolution
Prerequisites
You have access to root, admin, and sshuser passwords.
Validating Services from the Command Line Interface (CLI)
Confirm available disk space by reviewing the output of the below command:
df -h
Confirm the below services are running.
service horizon-workspace status; service elasticsearch status; /etc/init.d/opensearch status; service pgService status; service vpostgres status
Note: Elasticsearch is removed from vIDM versions 3.3.7 and above. It is replaced by OpenSearch. The PgService runs only in clustered environments. See KB75080 referenced previously in this article for additional information on validating a Postgres cluster from the CLI.
Confirm DNS is configured properly by running the following commands and validating their output:
nslookup $( iface-ip eth0); nslookup $( uname -n)
VMware Identity Manager Best Practices
Keep all passwords updated in VMware Aria Suite Lifecycle Locker. Operational maintenance of the root password should be done within Aria Suite Lifecycle Locker exclusively, unless absolutely necessary. Aria Suite Lifecycle has scheduled health replication delays between nodes in a cluster. For more information see:
Remove old snapshots from any appliances. Snapshots should only be used temporarily for changes if daily backups are not available. Snapshots are not a long-term backup solution. See Best practices for using VMware snapshots in the vSphere environment for additional information.
Create frequent backups of the appliances.
Remove log bundles and database dumps. These files should not persist on the appliances and should be removed after they are generated and copied to support or offline for review.
VMware Aria Suite Lifecycle can be used to collect a log bundle from a cluster. It can be requested from the globalenvironment. Once the log bundle is collected, delete it from the appliance.
VMware Identity Manager clusters are SSL-terminated. During a certificate replacement:
Place the CA and Certificate Chain in the Load Balancer.
Appy them to the VIP.
Then, request the certificate replacement.
The wizard will suggest to re-trust the VMware Aria Products that are integrated with vIDM. This will cause downtime. This is required in other to avoid authentication issues. Optionally, you may trigger the re-trust later on the product page.