6.0.3

Table Of Contents
What to do next
Restart services on the Platform Services Controller. You can either restart the Platform Services Controller,
or run the following commands from the command line:
Windows
On Windows, the service-control command is located at
VCENTER_INSTALL_PATH\bin.
service-control --stop --all
service-control --start VMWareAfdService
service-control --start VMWareDirectoryService
service-control --start VMWareCertificateService
vCenter Server
Appliance
service-control --stop --all
service-control --start vmafdd
service-control --start vmdird
service-control --start vmcad
Managing Certificates with the vSphere Certificate Manager Utility
The vSphere Certicate Manager utility allows you to perform most certicate management tasks
interactively from the command line. vSphere Certicate Manager prompts you for the task to perform, for
certicate locations and other information as needed, and then stops and starts services and replaces
certicates for you.
If you use vSphere Certicate Manager, you are not responsible for placing the certicates in VECS
(VMware Endpoint Certicate Store) and you are not responsible for starting and stopping services.
Before you run vSphere Certicate Manager, be sure you understand the replacement process and procure
the certicates that you want to use.
C vSphere Certicate Manager supports one level of revert. If you run vSphere Certicate Manager
twice and notice that you unintentionally corrupted your environment, the tool cannot revert the rst of the
two runs.
You can run the tool on the command line as follows:
Windows
C:\Program Files\VMware\vCenter Server\vmcad\certificate-manager.bat
Linux
/usr/lib/vmware-vmca/bin/certificate-manager
1 Revert Last Performed Operation by Republishing Old Certicates on page 84
When you perform a certicate management operation by using vSphere Certicate Manager, the
current certicate state is stored in the BACKUP_STORE store in VECS before certicates are replaced.
You can revert the last performed operation and return to the previous state.
2 Reset All Certicates on page 84
Use the Reset All Certificates option if you want to replace all existing vCenter certicates with
certicates that are signed by VMCA.
3 Regenerate a New VMCA Root Certicate and Replace All Certicates on page 84
You can regenerate the VMCA root certicate, and replace the local machine SSL certicate, and the
local solution user certicates with VMCA-signed certicates. In multi-node deployments, run
vSphere Certicate Manager with this option on the Platform Services Controller and then run the
utility again on all other nodes and select
Replace Machine SSL certificate with VMCA Certificate and
Replace Solution user certificates with VMCA certificates.
Chapter 3 vSphere Security Certificates
VMware, Inc. 83