6.0.3

Table Of Contents
n
You plan to replace the default VMCA-signed certicates with custom certicates for the node on which
the vCenter Single Sign-On 6.0 service runs.
N In most other cases, upgrading the complete environment before restarting the services is best
practice. Teplacing the VMware Directory Service certicate is not usually recommended.
Procedure
1 On the node on which the vCenter Single Sign-On 6.0 service runs, replace the vmdird SSL certicate
and key.
See “Replace the VMware Directory Service Certicate,” on page 110.
2 On the node on which the vCenter Single Sign-On 5.5 service runs, set up the environment so the
vCenter Single Sign-On 6.0 service is known.
a Back up all les C:\ProgramData\VMware\CIS\cfg\vmdird.
b Make a copy of the vmdircert.pem le on the 6.0 node, and rename it to
<sso_node2.domain.com>.pem, where <sso_node2.domain.com> is the FQDN of the 6.0 node.
c Copy the renamed certicate to C:\ProgramData\VMware\CIS\cfg\vmdird to replace the existing
replication certicate.
3 Restart the VMware Directory Service on all machines where you replaced certicates.
You can restart the service from the vSphere Web Client or use the service-control command.
Managing Certificates and Services with CLI Commands
A set of CLIs allows you to manage VMCA ( VMware Certicate Authority), VECS (VMware Endpoint
Certicate Store), and VMware Directory Service (vmdir). The vSphere Certicate Manager utility supports
many related tasks as well, but the CLIs are required for manual certicate management.
Table 35. CLI Tools for Managing Certificates and Associated Services
CLI Description See
certool
Generate and manage certicates and
keys. Part of VMCA.
“certool Initialization Commands
Reference,” on page 120
vecs-cli
Manage the contents of VMware
Certicate Store instances. Part of
VMAFD.
“vecs-cli Command Reference,” on
page 125
dir-cli
Create and update certicates in
VMware Directory Service. Part of
VMAFD.
“dir-cli Command Reference,” on
page 128
service-control
Start or stop services, for example as
part of a certicate replacement
workow
Certificate Management Tool Locations
By default, you nd the tools in the following locations on each node.
Windows
C:\Program Files\VMware\vCenter Server\vmafdd\vecs-cli.exe
C:\Program Files\VMware\vCenter Server\vmafdd\dir-cli.exe
C:\Program Files\VMware\vCenter Server\vmcad\certool.exe
VCENTER_INSTALL_PATH\bin
Linux
/usr/lib/vmware-vmafd/bin/vecs-cli
vSphere Security
118 VMware, Inc.