6.0.3

Table Of Contents
Prerequisites
1 Generate the CSR.
2 Edit the certicate that you receive, and place the current VMCA root certicate at the boom.
“Generate Certicate Signing Requests with vSphere Certicate Manager (Intermediate CA),” on page 85
explains both steps.
Procedure
1 From a Web browser, connect to the Platform Services Controller by specifying the following URL:
https://psc_hostname_or_IP/psc
In an embedded deployment, the Platform Services Controller host name or IP address is the same as
the vCenter Server host name or IP address.
2 Specify the user name and password for administrator@vsphere.local or another member of the vCenter
Single Sign-On Administrators group.
If you specied a dierent domain during installation, log in as administrator@mydomain.
3 To replace the existing certicate with the chained certicate, follow these steps:
a Under Certicates, click  Authority and select the Root  tab.
b Click Replace . add the private key le and the certicate le (full chain) and click OK.
c In the Replace Root  dialog, click Browse and select the private key, click Browse again
and select the certicate, and click OK.
Going forward, VMCA signs all certicates that it issues with the new chained root certicate.
4 Renew the machine SSL certicate for the local system.
a Under Certicates, click  Management and click the Machine  tab.
b Select the certicate, click Renew, and answer Yes to the prompt.
VMCA replaces the machine SSL certicate with the certicate that is signed by the new CA.
5 (Optional) Renew the solution user certicates for the local system.
a Click the Solution User  tab.
b Select a certicate and click Renew to renew individual selected certicates, or click Renew All to
replace all certicates and answer Yes to the prompt.
VMCA replaces the solution user certicate or all solution user certicates with certicates that are
signed by the new CA.
6 If your environment includes an external Platform Services Controller, you can then renew the
certicates for each of the vCenter Server system.
a Click the Logout buon in the Certicate Management panel.
b When prompted, specify the IP address or FQDN of the vCenter Server system and user name and
password of a vCenter Server administrator who can authenticate to vCenter Single Sign-On.
c Renew the machine SSL certicate on the vCenter Server and, optionally, each solution user
certicate.
d If you have multiple vCenter Server systems in your environment, repeat the process for each
system.
Chapter 3 vSphere Security Certificates
VMware, Inc. 79