6.0.3

Table Of Contents
3 Select  Valid To, click OK, and scroll to the right if necessary.
The certicate information displays when the certicate expires.
If a host is added to vCenter Server or reconnected after a disconnect, vCenter Server renews the
certicate if the status is Expired, Expiring, Expiring shortly, or Expiration imminent. The status is
Expiring if the certicate is valid for less than eight months, Expiring shortly if the certicate is valid for
less than two months, and Expiration imminent if the certicate is valid for less than one month.
4 (Optional) Deselect other columns to make it easier to see what you are interested in.
What to do next
Renew the certicates that are about to expire. See “Renew or Refresh ESXi Certicates,” on page 164.
View Certificate Details for a Single ESXi Host
For ESXi 6.0 and later hosts that are in VMCA mode or custom mode, you can view certicate details from
the vSphere Web Client. The information about the certicate can be helpful for debugging.
Procedure
1 Browse to the host in the vSphere Web Client inventory.
2 Click the Manage tab and click .
3 Select System, and click .
You can examine the following information. This information is available only in the single-host view.
Field Description
Subject
The subject used during certicate generation.
Issuer
The issuer of the certicate.
Valid From
Date on which the certicate was generated.
Valid To
Date on which the certicate expires.
Status
Status of the certicate, one of the following.
Good
Normal operation.
Expiring
Certicate will expire soon.
Expiring shortly
Certicate is 8 months or less away from expiration
(Default).
Expiration
imminent
Certicate is 2 months or less away from expiration
(Default).
Expired
Certicate is not valid because it expired.
Renew or Refresh ESXi Certificates
If VMCA assigns certicates to your ESXi hosts (6.0 and later), you can renew those certicates from the
vSphere Web Client. You can also refresh all certicates from the TRUSTED_ROOTS store associated with
vCenter Server.
You can renew your certicates when they are about to expire, or if you want to provision the host with a
new certicate for other reasons. If the certicate is already expired, you must disconnect the host and
reconnect it.
By default, vCenter Server renews the certicates of a host with status Expired, Expiring immediately, or
Expiring each time the host is added to the inventory, or reconnected.
vSphere Security
164 VMware, Inc.