6.0.3

Table Of Contents
2 On the node on which the vCenter Single Sign-On 5.5 service runs, set up the environment so the
vCenter Single Sign-On 6.0 service is known.
a Back up all les C:\ProgramData\VMware\CIS\cfg\vmdird.
b Make a copy of the vmdircert.pem le on the 6.0 node, and rename it to
<sso_node2.domain.com>.pem, where <sso_node2.domain.com> is the FQDN of the 6.0 node.
c Copy the renamed certicate to C:\ProgramData\VMware\CIS\cfg\vmdird to replace the existing
replication certicate.
3 Restart the VMware Directory Service on all machines where you replaced certicates.
You can restart the service from the vSphere Web Client or use the service-control command.
Use Third-Party Certificates With vSphere
If company policy requires it, you can replace all certicates used in vSphere with third-party CA-signed
certicates. If you do that, VMCA is not in your certicate chain but all vCenter certicates have to be stored
in VECS.
You can replace all certicates or use a hybrid solution. For example, consider replacing all certicates that
are used for network trac but leaving VMCA-signed solution user certicates. Solution user certicates are
used only for authentication to vCenter Single Sign-On, in place.
N If you do not want to use VMCA, you are responsible for replacing all certicates yourself, for
provisioning new components with certicates, and for keeping track of certicate expiration.
Procedure
1 Request Certicates and Import a Custom Root Certicate on page 113
If company policy does not allow an intermediate CA, VMCA cannot generate the certicates for you.
You use custom certicates from an enterprise or third-party CA.
2 Replace Machine SSL Certicates With Custom Certicates on page 114
After you receive the custom certicates, you can replace each machine certicate.
3 Replace Solution User Certicates With Custom Certicates on page 115
After you replace the machine SSL certicates, you can replace the VMCA-signed solution user
certicates with third-party or enterprise certicates.
4 Replace the VMware Directory Service Certicate on page 117
If you decide to use a new VMCA root certicate, and you unpublish the VMCA root certicate that
was used when you provisioned your environment, you must replace the machine SSL certicates,
solution user certicates, and certicates for some internal services.
5 Replace the VMware Directory Service Certicate in Mixed Mode Environments on page 117
During upgrade, your environment might temporarily include both vCenter Single Sign-On version
5.5 and vCenter Single Sign-On version 6.0, you have to perform additional steps to replace the
VMware Directory Service SSL certicate if you replace the SSL certicate of the node on which the
vCenter Single Sign-On service is running.
vSphere Security
112 VMware, Inc.