6.0.3

Table Of Contents
vCenter Certificate Interfaces
For vCenter Server, you can view and replace certicates with the following tools and interfaces.
vSphere Certificate
Manager utility
Perform all common certicate replacement tasks from the command-line.
Certificate management
CLIs
Perform all certicate management tasks with dir-cli, certool, and vecs-
cli.
vSphere Web Client
certificate management
View certicates, including expiration information.
For ESXi, you perform certicate management from the vSphere Web Client. Certicates are provisioned by
VMCA and are stored only locally on the ESXi host, not in vmdir or VECS. See “Certicate Management for
ESXi Hosts,” on page 160.
Supported vCenter Certificates
For vCenter Server, the Platform Services Controller, and related machines and services, the following
certicates are supported:
n
Certicates that are generated and signed by VMware Certicate Authority (VMCA).
n
Custom certicates.
n
Enterprise certicates that are generated from your own internal PKI.
n
Third-party CA-signed certicates that are generated by an external PKI such as Verisign,
GoDaddy, and so on.
Self-signed certicates that were created using OpenSSL in which no Root CA exists are not supported.
Certificate Replacement Overview
You can perform dierent types of certicate replacement depending on company policy and requirements
for the system that you are conguring. You can perform each replacement with the vSphere Certicate
Manager utility or manually by using the CLIs included with your installation.
You can replace the default certicates. For vCenter Server components, you can use a set of command-line
tools included in your installation. You have several options.
Replace With Certificates Signed by VMCA
If your VMCA certicate expires or you want to replace it for other reasons, you can use the certicate
management CLIs to perform that process. By default, the VMCA root certicate expires after ten years, and
all certicates that VMCA signs expire when the root certicate expires, that is, after a maximum of ten
years.
Chapter 3 vSphere Security Certificates
VMware, Inc. 67