VMware Workspace ONE Community
JimMalandruccol
Contributor
Contributor

Tunnel SSL Certificate Renewal

Hey all, we have run into a snag renewing our Third-Party Proxy and Per-App SSL certificates. When attempting to upload we get an error ' Please upload a valid certificate chain.'  However the chain does appear to be valid as it has been uploaded for profile signing and IIS for AWCM with no issues. We are working to get he pfx file recreated to try again but if we cannot get it figured out is there any downside to not using a third-party certificate and using the default AirWatch cert? We are using Proxy for Browser/Web access and Per-App VPN with only a few third party apps.
This is an on-prem console version 9.2.3 with a single VMWare Tunnel in Basic configuration.

Thanks.
Labels (1)
Reply
0 Kudos
11 Replies
PatrickKoza
Contributor
Contributor

i have the same Problem.
Someone can help?
Reply
0 Kudos
snochico1
Enthusiast
Enthusiast

I assume you are running the tunnel install on Linux ?   From what I remember we had to load the root and the intermediate certificates int the Java keystore .  I will try and look at my notes when I get into the office. 
Reply
0 Kudos
PatrickKoza
Contributor
Contributor

No, on a Windows over Webinterface.
When i Upload the Cert, i get the error ' invalid certificate chain' .
Reply
0 Kudos
LukeDC
Expert
Expert

I recommend this tool to help repair certs etc. Believe it works for all certs, not just DigiCert:

https://www.digicert.com/util/
Reply
0 Kudos
LukeDC
Expert
Expert

also you need to upload a .p12 cert to WS1, they don't accept pfx certs.
Reply
0 Kudos
PatrickKoza
Contributor
Contributor

Really? The Airwatch Console says: .p12 or .pfx :disappointed_face:
So, i will try a .p12
Reply
0 Kudos
PatrickKoza
Contributor
Contributor

Same Problem ' Invald cert chain'
Reply
0 Kudos
NileshKadamNile
Contributor
Contributor

i have the same Problem.
Someone can help?
Reply
0 Kudos
NileshKadamNile
Contributor
Contributor

Erorr ' Please upload a valid certificate chain.'
Reply
0 Kudos
Stansfield
Enthusiast
Enthusiast

Did you include the full chain entirely in the cert?  IIS will accept intermediate certs elsewhere and AWCM will work (although it is questionably wise) without the full cert chain.  Also I do not know of any downsides to using the AirWatch certs nothing not configured by the system connects to it (or is desired to connect) so trust by other systems is irrelevant.
Reply
0 Kudos
DimitrisTsaktsi
Contributor
Contributor

Dear All,

I am facing the same issue. I tried to upload another certificate from the same CA and accepted successfully. It seems that it doesn't accept some certificates. Any idea why it fails?
Thank you in advance.

Best regards,
Dimitris
Reply
0 Kudos