6.0.3

Table Of Contents
Explore Certificate Stores from the Platform Services Controller Web Interface
A VMware Endpoint Certicate Store (VECS) instance is included on each Platform Services Controller node
and each vCenter Server node. You can explore the dierent stores inside the VMware Endpoint Certicate
Store from the Platform Services Controller web interface.
See “VMware Endpoint Certicate Store Overview,” on page 72 for details on the dierent stores inside
VECS.
Prerequisites
For most management tasks, you must have the password for the administrator for the local domain
account, administrator@vsphere.local or a dierent domain if you changed the domain during installation.
Procedure
1 From a Web browser, connect to the Platform Services Controller by specifying the following URL:
https://psc_hostname_or_IP/psc
In an embedded deployment, the Platform Services Controller host name or IP address is the same as
the vCenter Server host name or IP address.
2 Specify the user name and password for administrator@vsphere.local or another member of the vCenter
Single Sign-On Administrators group.
If you specied a dierent domain during installation, log in as administrator@mydomain.
3 Under Certicates, click  Store and explore the store.
4 Select the store inside the VMware Endpoint Certicate Store (VECS) that you want to explore from the
pulldown menu.
“VMware Endpoint Certicate Store Overview,” on page 72 explains what's in the individual stores.
5 To view details for a certicate, select the certicate and click the Show Details icon.
6 To delete an entry from the selected store, click the Delete Entry icon.
For example, if you replace the existing certicate, you can later remove the old root certicate. Remove
certicates only if you are sure that they are no longer in use.
Replace Certificates with New VMCA-Signed Certificates from the
Platform Services Controller Web Interface
You can replace all VMCA-signed certicates with new VMCA-signed certicates; this process is called
renewing certicates. You can renew selected certicates or all certicates in your environment from the
Platform Services Controller web interface.
Prerequisites
For certicate management, you have to supply the password of the administrator of the local domain
(administrator@vsphere.local by default). If you are renewing certicates for a vCenter Server system, you
also have to supply the vCenter Single Sign-On credentials for a user with administrator privileges on the
vCenter Server system.
Procedure
1 From a Web browser, connect to the Platform Services Controller by specifying the following URL:
https://psc_hostname_or_IP/psc
In an embedded deployment, the Platform Services Controller host name or IP address is the same as
the vCenter Server host name or IP address.
Chapter 3 vSphere Security Certificates
VMware, Inc. 77