6.0.2

Table Of Contents
Host Upgrades and Certificates
If you upgrade an ESXi host to ESXi 6.0 or later, the upgrade process replaces the self-signed (thumbprint)
certicates with VMCA-signed certicates. If the ESXi host uses custom certicates, the upgrade process
retains those certicates even if those certicates are expired or invalid.
If you decide not to upgrade your hosts to ESXi 6.0 or later, the hosts retain the certicates that they are
currently using even if the host is managed by a vCenter Server system that uses VMCA certicates.
The recommended upgrade workow depends on the current certicates.
Host Provisioned with
Thumbprint Certificates
If your host is currently using thumbprint certicates, it is automatically
assigned VMCA certicates as part of the upgrade process.
N You cannot provision legacy hosts with VMCA certicates. You must
upgrade those hosts to ESXi 6.0 later.
Host Provisioned with
Custom Certificates
If your host is provisioned with custom certicates, usually third-party CA-
signed certicates, those certicates remain in place during upgrade. Change
the certicate mode to Custom to ensure that the certicates are not replaced
accidentally during a certicate refresh later.
N If your environment is in VMCA mode, and you refresh the
certicates from the vSphere Web Client, any existing certicates are
replaced with certicates that are signed by VMCA.
Going forward, vCenter Server monitors the certicates and displays
information, for example, about certicate expiration, in the
vSphere Web Client.
Hosts Provisioned with
Auto Deploy
Hosts that are being provisioned by Auto Deploy are always assigned new
certicates when they are rst booted with ESXi 6.0 or later software. When
you upgrade a host that is provisioned by Auto Deploy, the Auto Deploy
server generates a certicate signing request (CSR) for the host and submits it
to VMCA. VMCA stores the signed certicate for the host. When the Auto
Deploy server provisions the host, it retrieves the certicate from VMCA and
includes it as part of the provisioning process.
You can use Auto Deploy with custom certicates.
Change the Certificate Mode
In most cases, using VMCA to provision the ESXi hosts in your environment is the best solution. If corporate
policy requires that you use custom certicates with a dierent root CA, you can edit the vCenter Server
advanced options so that the hosts are not automatically provisioned with VMCA certicates when you
refresh certicates. You are then responsible for the certicate management in your environment.
You can use the vCenter Server advanced seings to change to thumbprint mode or to custom CA mode.
Use thumbprint mode only as a fallback option.
Procedure
1 Select the vCenter Server that manages the hosts and click .
2 Click Advanced , and click Edit.
3 In the Filter box, enter certmgmt to display only certicate management keys.
Chapter 5 Preparing for Migration
VMware, Inc. 29