6.0.3

Table Of Contents
/usr/lib/vmware-vmafd/bin/dir-cli
/usr/lib/vmware-vmca/bin/certool
On Linux, the service-control command does not require that you specify the
path.
If you run commands from a management node with an external Platform Services Controller, you can
specify the Platform Services Controller with the --server parameter.
Required Privileges for Certificate Management Operations
For most vCenter certicate management operations, you have to be in the CAAdmins group in the
vsphere.local domain. The administrator@vsphere.local user is in the CAAdmins group. Some operations
are allowed for all users.
If you run the vCenter Certicate Manager utility, you are prompted for the password of
administrator@vsphere.local. If you replace certicates manually, dierent options for the dierent
certicate management CLIs require dierent privileges.
dir-cli
You must be a member of the CAAdmins group in the vsphere.local domain.
You are prompted for a user name and password each time you run a dir-
cli command.
vecs-cli
Initially, only the store owner has access to a store. The store owner is the
Administrator user on Windows systems and the root user on Linux systems.
The store owner can provide access to other users.
The MACHINE_SSL_CERT and TRUSTED_ROOTS stores are special stores.
Only the root user or administrator user, depending on the type of
installation, has complete access.
certool
Most of the certool commands require that the user is in the CAAdmins
group. The administrator@vsphere.local user is in the CAAdmins group. All
users can run the following commands:
n
genselfcacert
n
initscr
n
getdc
n
waitVMDIR
n
waitVMCA
n
genkey
n
viewcert
For certicate management for ESXi hosts, you must have the . Manage  privilege.
You can set that privilege from the vSphere Web Client.
Chapter 3 vSphere Security Certificates
VMware, Inc. 119