6.0.3

Table Of Contents
4 Make VMCA an Intermediate Certicate Authority (Certicate Manager) on page 85
You can make VMCA an Intermediate CA by following the prompts from Certicate Manager utility.
After you complete the process, VMCA signs all new certicates with the full chain. If you want, you
can use Certicate Manager to replace all existing certicates with new VMCA-signed certicates.
5 Replace All Certicates with Custom Certicate (Certicate Manager) on page 89
You can use the vSphere Certicate Manager utility to replace all certicates with custom certicates.
Before you start the process, you must send CSRs to your CA. You can use Certicate Manager to
generate the CSRs.
Revert Last Performed Operation by Republishing Old Certificates
When you perform a certicate management operation by using vSphere Certicate Manager, the current
certicate state is stored in the BACKUP_STORE store in VECS before certicates are replaced. You can
revert the last performed operation and return to the previous state.
N The revert operation restores what is currently in the BACKUP_STORE. If you run vSphere
Certicate Manager with two dierent options and you then aempt to revert, only the last operation is
reverted.
Reset All Certificates
Use the Reset All Certificates option if you want to replace all existing vCenter certicates with
certicates that are signed by VMCA.
When you use this option, you overwrite all custom certicates that are currently in VECS.
n
On a Platform Services Controller node, vSphere Certicate Manager can regenerate the root certicate
and replace the machine SSL certicate and the machine solution user certicate.
n
On a management node, vSphere Certicate Manager can replace the machine SSL certicate and all
solution user certicates.
n
In an embedded deployment, vSphere Certicate Manager can replace all certicates.
Which certicates are replaced depends on which options you select.
Regenerate a New VMCA Root Certificate and Replace All Certificates
You can regenerate the VMCA root certicate, and replace the local machine SSL certicate, and the local
solution user certicates with VMCA-signed certicates. In multi-node deployments, run vSphere
Certicate Manager with this option on the Platform Services Controller and then run the utility again on all
other nodes and select Replace Machine SSL certificate with VMCA Certificate and
Replace Solution user certificates with VMCA certificates.
When you run this command, vSphere Certicate Manager prompts you for the password and for certicate
information and stores all information, except for the password, in the certool.cfg le. After that, stopping
services, replacing all certicates, and restarting processes is automatic. You are prompted for the following
information:
n
Password for administrator@vsphere.local.
n
Two-leer country code
n
Company name
n
Organization name
n
Organization unit
n
State
vSphere Security
84 VMware, Inc.