6.0.3

Table Of Contents
n
Gather the information you will need.
n
Password for administrator@vsphere.local.
n
Valid custom certicate for Root (.crt le).
n
Valid custom key for Root (.key le).
Procedure
1 Start vSphere Certicate Manager on an embedded installation or on an external
Platform Services Controller and select option 2.
2 Select option 2 to start certicate replacement and respond to the prompts.
a Specify the full path to the root certicate when prompted.
b If you are replacing certicates for the rst time, you are prompted for information to be used for
the machine SSL certicate.
This information includes the required FQDN of the machine and is stored in the certool.cfg le.
3 If you replace the root certicate in a multi-node deployment, you must restart services on all
vCenter Server.
4 In multi-node deployments, regenerate all certicates on each vCenter Server instances by using
options 3 (Replace Machine SSL certicate with VMCA Certicate) and 6 ( Replace Solution user
certicates with VMCA certicates).
When you replace the certicates, VMCA signs with the full chain.
What to do next
Depending on your environment, you might have to replace additional certicates explicitly.
n
If company policy requires that you replace all certicates, replace the vmdir root certicate. See
“Replace the VMware Directory Service Certicate,” on page 110
n
If you are upgrading from a vSphere 5.x environment, you might have to replace the vCenter Single
Sign-On certicate inside vmdir. See “Replace the VMware Directory Service Certicate in Mixed Mode
Environments,” on page 101
Replace Machine SSL Certificate with VMCA Certificate (Intermediate CA)
In a multi-node deployment that uses VMCA as an intermediate CA, you have to replace the machine SSL
certicate explicitly. First you replace the VMCA root certicate on the Platform Services Controller node,
and then you can replace the certicates on the vCenter Server nodes to have the certicates signed by the
full chain. You can also use this option to replace machine SSL certicates that are corrupt or about to expire.
When you replace the existing machine SSL certicate with a new VMCA-signed certicate, vSphere
Certicate Manager prompts you for information and enters all values, except for the password and the IP
address of the Platform Services Controller, into the certool.cfg le.
n
Password for administrator@vsphere.local.
n
Two-leer country code
n
Company name
n
Organization name
n
Organization unit
n
State
n
Locality
Chapter 3 vSphere Security Certificates
VMware, Inc. 87