6.0.3

Table Of Contents
What to do next
Restart services on the Platform Services Controller. You can either restart the Platform Services Controller,
or run the following commands from the command line:
Windows
On Windows, the service-control command is located at
VCENTER_INSTALL_PATH\bin.
service-control --stop --all
service-control --start VMWareAfdService
service-control --start VMWareDirectoryService
service-control --start VMWareCertificateService
vCenter Server
Appliance
service-control --stop --all
service-control --start vmafdd
service-control --start vmdird
service-control --start vmcad
Set up Your System to Use Custom Certificates from the Platform Services
Controller
You can use the Platform Services Controller to set up your environment to use custom certicates.
You can generate Certicate Signing Requests (CSRs) for each machine and for each solution user using the
Certicate Manager utility. When you submit the CSRs to your internal or third-party CA, the CA returns
signed certicates and the root certicate. You can upload both the root certicate and the signed certicates
from the Platform Services Controller UI.
Generate Certificate Signing Requests with vSphere Certificate Manager (Custom
Certificates)
You can use vSphere Certicate Manager to generate Certicate Signing Requests (CSRs) that you can then
use with your enterprise CA or send to an external certicate authority. You can use the certicates with the
dierent supported certicate replacement processes.
You can run the Certicate Manager tool from the command line as follows:
Windows
C:\Program Files\VMware\vCenter Server\vmcad\certificate-manager.bat
Linux
/usr/lib/vmware-vmca/bin/certificate-manager
Prerequisites
vSphere Certicate Manager prompts you for information. The prompts depend on your environment and
on the type of certicate you want to replace.
n
For any CSR generation, you are prompted for the password of the administrator@vsphere.local user, or
for the administrator of the vCenter Single Sign-On domain that you are connecting to.
n
If you are generating a CSR in an environment with an external Platform Services Controller, you are
prompted for the host name or IP address of the Platform Services Controller.
n
To generate a CSR for a machine SSL certicate, you are prompted for certicate properties, which are
stored in the certool.cfg le. For most elds, you can accept the default or provide site-specic values.
The FQDN of the machine is required.
Procedure
1 On each machine in your environment, start vSphere Certicate Manager and select option 1.
2 Supply the password and the Platform Services Controller IP address or host name if prompted.
vSphere Security
80 VMware, Inc.