6.0.3

Table Of Contents
vSphere Security Certificates 3
vSphere components use SSL to communicate securely with each other and with ESXi. SSL communications
ensure data condentiality and integrity. Data is protected, and cannot be modied in transit without
detection.
Certicates are also used by vCenter Server services such as the vSphere Web Client for initial
authentication to vCenter Single Sign-On. vCenter Single Sign-On provisions each component with a SAML
token that the component uses for authentication going forward.
In vSphere 6.0 and later, the VMware Certicate Authority (VMCA) provisions each ESXi host and each
vCenter Server service with a certicate that is signed by VMCA by default.
You can replace the existing certicates with new VMCA-signed certicates, make VMCA a subordinate CA,
or replace all certicates with custom certicates. You have several options:
Table 31. Different Approaches to Certificate Replacement
Option See
Use the Platform Services Controller web interface
(vSphere 6.0 Update 1 and later).
“Managing Certicates with the Platform Services
Controller Web Interface,” on page 76
Use the vSphere Certicate Manager utility from the
command line.
“Managing Certicates with the vSphere Certicate
Manager Utility,” on page 83
Use CLI commands for manual certicate replacement. “Managing Certicates and Services with CLI Commands,”
on page 118
vSphere Certicate Management
(hp://link.brightcove.com/services/player/bcpid2296383276001?
bctid=ref:video_vsphere6_cert_infrastructure)
This chapter includes the following topics:
n
“Certicate Management Overview,” on page 66
n
“Managing Certicates with the Platform Services Controller Web Interface,” on page 76
n
“Managing Certicates with the vSphere Certicate Manager Utility,” on page 83
n
“Manual Certicate Replacement,” on page 92
n
“Managing Certicates and Services with CLI Commands,” on page 118
n
“View vCenter Certicates with the vSphere Web Client,” on page 133
n
“Set the Threshold for vCenter Certicate Expiration Warnings,” on page 133
VMware, Inc.
65