6.0.3

Table Of Contents
vecs-cli store list
List certicate stores.
VECS includes the following stores.
Table 36. Stores in VECS
Store Description
Machine SSL store (MACHINE_SSL_CERT)
n
Used by the reverse proxy service on every vSphere
node.
n
Used by the VMware Directory Service (vmdir) on
embedded deployments and on each
Platform Services Controller node.
All services in vSphere 6.0 communicate through a reverse
proxy, which uses the machine SSL certicate. For
backward compatibility, the 5.x services still use specic
ports. As a result, some services such as vpxd still have
their own port open.
Trusted root store (TRUSTED_ROOTS) Contains all trusted root certicates.
Solution user stores
n
machine
n
vpxd
n
vpxd-extensions
n
vsphere-webclient
VECS includes one store for each solution user. The subject
of each solution user certicate must be unique, for
example, the machine certicate cannot have the same
subject as the vpxd certicate.
Solution user certicates are used for authentication with
vCenter Single Sign-On. vCenter Single Sign-On checks
that the certicate is valid, but does not check other
certicate aributes. In an embedded deployment, all
solution user certicates are on the same system.
The following solution user certicate stores are included
in VECS on each management node and each embedded
deployment:
n
machine: Used by component manager, license server,
and the logging service.
N The machine solution user certicate has
nothing to do with the machine SSL certicate. The
machine solution user certicate is used for the SAML
token exchange; the machine SSL certicate is used for
secure SSL connections for a machine.
n
vpxd: vCenter service daemon (vpxd) store on
management nodes and embedded deployments. vpxd
uses the solution user certicate that is stored in this
store to authenticate to vCenter Single Sign-On.
n
vpxd-extensions: vCenter extensions store. Includes
the Auto Deploy service, inventory service, and other
services that are not part of other solution users.
n
vsphere-webclient: vSphere Web Client store. Also
includes some additional services such as the
performance chart service.
The machine store is also included on each
Platform Services Controller node.
vSphere Security
126 VMware, Inc.