6.0.3

Table Of Contents
Switching from Thumbprint Mode to VMCA Mode
If you use thumbprint mode and you want to start using VMCA-signed certicates, the switch requires
some planning. The recommended workow is as follows.
1 Remove all hosts from the vCenter Server system.
2 Switch to VMCA certicate mode. See “Change the Certicate Mode,” on page 167.
3 Add the hosts to the vCenter Server system.
N Any other workow for this mode switch might result in unpredictable behavior.
Switching from Custom CA Mode to Thumbprint Mode
If you are encountering problems with your custom CA, consider switching to thumbprint mode
temporarily. The switch works seamlessly if you follow the instructions in “Change the Certicate Mode,”
on page 167. After the mode switch, the vCenter Server system checks only the format of the certicate and
no longer checks the validity of the certicate itself.
Switching from Thumbprint Mode to Custom CA Mode
If you set your environment to thumbprint mode during troubleshooting, and you want to start using
custom CA mode, you must rst generate the required certicates. The recommended workow is as
follows.
1 Remove all hosts from the vCenter Server system.
2 Add the custom CA root certicate to TRUSTED_ROOTS store on VECS on the vCenter Server system.
See “Update the vCenter Server TRUSTED_ROOTS Store (Custom Certicates),” on page 170.
3 For each ESXi host:
a Deploy the custom CA certicate and key.
b Restart services on the host.
4 Switch to custom mode. See “Change the Certicate Mode,” on page 167.
5 Add the hosts to the vCenter Server system.
Change the Certificate Mode
In most cases, using VMCA to provision the ESXi hosts in your environment is the best solution. If corporate
policy requires that you use custom certicates with a dierent root CA, you can edit the vCenter Server
advanced options so that the hosts are not automatically provisioned with VMCA certicates when you
refresh certicates. You are then responsible for the certicate management in your environment.
You can use the vCenter Server advanced seings to change to thumbprint mode or to custom CA mode.
Use thumbprint mode only as a fallback option.
Procedure
1 Select the vCenter Server that manages the hosts and click .
2 Click Advanced , and click Edit.
3 In the Filter box, enter certmgmt to display only certicate management keys.
4 Change the value of vpxd.certmgmt.mode to custom if you intend to manage your own certicates, and
to thumbprint if you temporarily want to use thumbprint mode, and click OK.
5 Restart the vCenter Server service.
Chapter 5 Securing ESXi Hosts
VMware, Inc. 167