6.0.3

Table Of Contents
f Replace the vsphere-webclient solution user certicate on each management node. For example, if
vsphere-webclient-6fd7f140-60a9-11e4-9e28-005056895a69 is the vsphere-webclient solution user
ID, run this command:
C:\>"C:\Program Files\VMware\vCenter Server\vmafdd\"dir-cli service update --name
vsphere-webclient-6fd7f140-60a9-11e4-9e28-005056895a69 --cert new-vsphere-webclient.crt
What to do next
Restart all services on each Platform Services Controller node and each management node.
Replace the VMware Directory Service Certificate in Mixed Mode Environments
During upgrade, your environment might temporarily include both vCenter Single Sign-On version 5.5 and
vCenter Single Sign-On version 6.0, you have to perform additional steps to replace the VMware Directory
Service SSL certicate if you replace the SSL certicate of the node on which the vCenter Single Sign-On
service is running.
The VMware Directory Service SSL certicate is used by vmdir to perform handshakes between
Platform Services Controller nodes that perform vCenter Single Sign-On replication
These steps are required only if:
n
Your environment includes both vCenter Single Sign-On 5.5 and vCenter Single Sign-On 6.0 services.
n
The vCenter Single Sign-On services are set up to replicate vmdir data.
n
You plan to replace the default VMCA-signed certicates with custom certicates for the node on which
the vCenter Single Sign-On 6.0 service runs.
N In most other cases, upgrading the complete environment before restarting the services is best
practice. Teplacing the VMware Directory Service certicate is not usually recommended.
Procedure
1 On the node on which the vCenter Single Sign-On 6.0 service runs, replace the vmdird SSL certicate
and key.
See “Replace the VMware Directory Service Certicate,” on page 110.
2 On the node on which the vCenter Single Sign-On 5.5 service runs, set up the environment so the
vCenter Single Sign-On 6.0 service is known.
a Back up all les C:\ProgramData\VMware\CIS\cfg\vmdird.
b Make a copy of the vmdircert.pem le on the 6.0 node, and rename it to
<sso_node2.domain.com>.pem, where <sso_node2.domain.com> is the FQDN of the 6.0 node.
c Copy the renamed certicate to C:\ProgramData\VMware\CIS\cfg\vmdird to replace the existing
replication certicate.
3 Restart the VMware Directory Service on all machines where you replaced certicates.
You can restart the service from the vSphere Web Client or use the service-control command.
Chapter 3 vSphere Security Certificates
VMware, Inc. 101