6.0.3

Table Of Contents
2 Specify the user name and password for administrator@vsphere.local or another member of the vCenter
Single Sign-On Administrators group.
If you specied a dierent domain during installation, log in as administrator@mydomain.
3 Under Certicates, select  Management and specify the IP address or host name for the
Platform Services Controller and the user name and password of the administrator of the local domain
(administrator@vsphere.local by default), and click Submit.
4 Renew the machine SSL certicate for the local system.
a Click the Machine  tab.
b Select the certicate, click Renew, and answer Yes to the prompt.
5 (Optional) Renew the solution user certicates for the local system.
a Click the Solution User  tab.
b Select a certicate and click Renew to renew individual selected certicates, or click Renew All to
renew all solution user certicates.
c Answer Yes at the prompt.
6 If your environment includes an external Platform Services Controller, you can then renew the
certicates for each of the vCenter Server system.
a Click the Logout buon in the Certicate Management panel.
b When prompted, specify the IP address or FQDN of the vCenter Server system and user name and
password of a vCenter Server administrator who can authenticate to vCenter Single Sign-On.
c Renew the machine SSL certicate on the vCenter Server and, optionally, each solution user
certicate.
d If you have multiple vCenter Server systems in your environment, repeat the process for each
system.
What to do next
Restart services on the Platform Services Controller. You can either restart the Platform Services Controller,
or run the following commands from the command line:
Windows
On Windows, the service-control command is located at
VCENTER_INSTALL_PATH\bin.
service-control --stop --all
service-control --start VMWareAfdService
service-control --start VMWareDirectoryService
service-control --start VMWareCertificateService
vCenter Server
Appliance
service-control --stop --all
service-control --start vmafdd
service-control --start vmdird
service-control --start vmcad
Make VMCA an Intermediate Certificate Authority from the
Platform Services Controller Web Interface
You can have the VMCA certicate signed by another CA so that VMCA becomes an intermediate CA
Going forward, all certicates that VMCA generates include the full chain.
You can perform this setup by using the vSphere Certicate Manager utility, by using CLIs, or from the
Platform Services Controller web interface.
vSphere Security
78 VMware, Inc.