6.0.3

Table Of Contents
Option Description
--account
Account name.
--current
Current password of the user who owns the account.
--new
New password of the user who owns the account.
View vCenter Certificates with the vSphere Web Client
You can view the certicates known to the vCenter Certicate Authority (VMCA) to see whether active
certicates are about to expire, to check on expired certicates, and to see the status of the root certicate.
You perform all certicate management tasks using the certicate management CLIs.
You view certicates associated with the VMCA instance that is included with your embedded deployment
or with the Platform Services Controller. Certicate information is replicated across instances of VMware
Directory Service (vmdir).
When you aempt to view certicates in the vSphere Web Client, you are prompted for a user name and
password. Specify the user name and password of a user with privileges for VMware Certicate Authority,
that is, a user in the CAAdmins vCenter Single Sign-On group.
Procedure
1 Log in to vCenter Server as administrator@vsphere.local or another user of the CAAdmins vCenter
Single Sign-On group.
2 Select Administration, click Deployment, and click System .
3 Click Nodes, and select the node for which you want to view or manage certicates.
4 Click the Manage tab, and click  Authority.
5 Click the certicate type for which you want to view certicate information.
Option Description
Active Certificates
Displays active certicates, including their validation information. The
green Valid To icon changes when certicate expiration is approaching.
Revoked Certificates
Displays the list of revoked certicates. Not supported in this release.
Expired Certificates
Lists expired certicates.
Root Certificates
Displays the root certicates available to this instance of vCenter
Certicate Authority.
6 Select a certicate and click the Show  Details buon to view certicate details.
Details include the Subject Name, Issuer, Validity, and Algorithm.
Set the Threshold for vCenter Certificate Expiration Warnings
Starting with vSphere 6.0, vCenter Server monitors all certicates in the VMware Endpoint Certicate Store
(VECS) and issues an alarm when a certicate is 30 days or less from its expiration. You can change how
soon you are warned with the vpxd.cert.threshold advanced option.
Procedure
1 Log in to the vSphere Web Client.
2 Select the vCenter Server object, the select the Manage tab and the  subtab.
3 Click Advanced , select Edit, and lter for threshold.
4 Change the seing of vpxd.cert.threshold to the desired value and click OK.
Chapter 3 vSphere Security Certificates
VMware, Inc. 133