6.0.3

Table Of Contents
n
Locality
n
IP address (optional)
n
Email
n
Host name, that is, the fully qualied domain name of the machine for which you want to replace the
certicate
n
IP address of Platform Services Controller if you are running the command on a management node
Prerequisites
You must know the FQDN of the machine for which you want to generate a new VMCA-signed certicate.
All other properties default to the predened values. The IP address is optional.
What to do next
After replacing the root certicate in a multi-node deployment, you must restart services on all
vCenter Server with external Platform Services Controller nodes.
Make VMCA an Intermediate Certificate Authority (Certificate Manager)
You can make VMCA an Intermediate CA by following the prompts from Certicate Manager utility. After
you complete the process, VMCA signs all new certicates with the full chain. If you want, you can use
Certicate Manager to replace all existing certicates with new VMCA-signed certicates.
Generate Certificate Signing Requests with vSphere Certificate Manager
(Intermediate CA)
You can use vSphere Certicate Manager to generate Certicate Signing Requests (CSRs). Submit those
CSRs to your enterprise CA or to an external certicate authority for signing. You can use the signed
certicates with the dierent supported certicate replacement processes.
Prerequisites
vSphere Certicate Manager prompts you for information. The prompts depend on your environment and
on the type of certicate you want to replace.
n
For any CSR generation, you are prompted for the password of the administrator@vsphere.local user, or
for the administrator of the vCenter Single Sign-On domain that you are connecting to.
n
If you are generating a CSR in an environment with an external Platform Services Controller, you are
prompted for the host name or IP address of the Platform Services Controller.
n
To generate a CSR for a machine SSL certicate, you are prompted for certicate properties, which are
stored in the certool.cfg le. For most elds, you can accept the default or provide site-specic values.
The FQDN of the machine is required.
Procedure
1 Start vSphere Certicate Manager and select option 2.
2 Supply the password and the Platform Services Controller IP address or host name if prompted.
3 Select option 1 to generate the CSR and answer the prompts.
As part of the process, you have to provide a directory. Certicate Manager places the les
root_signing_cert.csr and root_signing_cert.key in the directory.
4 Request or generate a certicate and name the le root_signing_cert.cer.
Chapter 3 vSphere Security Certificates
VMware, Inc. 85