6.0.3

Table Of Contents
n
“Replace Machine SSL Certicates With Custom Certicates,” on
page 114
Replacement of Solution User Certificates in Environments with Multiple
Management Nodes
If your environment includes multiple management nodes and a single Platform Services Controller, follow
these steps for certicate replacement.
N When you list solution user certicates in large deployments, the output of dir-cli list includes all
solution users from all nodes. Run vmafd-cli get-machine-id --server-name localhost to nd the local
machine ID for each host. Each solution user name includes the machine ID.
vSphere Certificate
Manager
You run vSphere Certicate Manager on each machine. On management
nodes, you are prompted for the IP address of the
Platform Services Controller. Depending on the task you perform, you are
also prompted for certicate information.
Manual Certificate
Replacement
1 Generate or request a certicate. You need the following certicates:
n
A certicate for the machine solution user on the
Platform Services Controller.
n
A certicate for the machine solution user on each management
node.
n
A certicate for each of the following solution users on each
management node:
n
vpxd solution user
n
vpxd-extension solution user
n
vsphere-webclient solution user
2 Replace the certicates on each node. The precise process depends on
the type of certicate replacement that you are performing. See
“Managing Certicates with the vSphere Certicate Manager Utility,” on
page 83
See the following topics for details:
n
“Replace Solution User Certicates With New VMCA-Signed
Certicates,” on page 97
n
“Replace Solution User Certicates (Intermediate CA),” on page 106
n
“Replace Solution User Certicates With Custom Certicates,” on
page 115
If company policy requires that you replace all certicates, you also have to replace the VMware Directory
Service (vmdir) certicate on the Platform Services Controller. See “Replace the VMware Directory Service
Certicate,” on page 110.
Chapter 3 vSphere Security Certificates
VMware, Inc. 75