6.0.3

Table Of Contents
n
IP address (optional)
n
Email
n
Host name, that is, the fully qualied domain name of the machine for which you want to replace the
certicate. If the host name does not match the FQDN, certicate replacement does not complete
correctly and your environment might end up in an unstable state.
n
IP address of Platform Services Controller if you are running the command on a management node
Prerequisites
n
Restart all vCenter Server nodes explicitly if you replaced the VMCA root certicate in a multi-node
deployment.
n
You must know the following information to run Certicate Manager with this option.
n
Password for administrator@vsphere.local.
n
The FQDN of the machine for which you want to generate a new VMCA-signed certicate. All
other properties default to the predened values but can be changed.
n
Host name or IP address of the Platform Services Controller if you are running on a vCenter Server
system with an external Platform Services Controller.
Procedure
1 Start vSphere Certicate Manager and select option 3.
2 Respond to the prompts.
Certicate Manager stores the information in the certool.cfg le.
vSphere Certicate Manager replaces the machine SSL certicate.
Replace Solution User Certificates with VMCA Certificates (Intermediate CA)
In a multi-node that uses VMCA as an intermediate CA, you must replace the solution user certicates
explicitly. First you replace the VMCA root certicate on the Platform Services Controller node, and then
you can replace the certicates on the vCenter Server nodes to have the certicates signed by the full chain.
You can also use this option to replace solution user certicates that are corrupt or about to expire.
Prerequisites
n
Restart all vCenter Server nodes explicitly if you replaced the VMCA root certicate in a multi-node
deployment.
n
You must know the following information to run Certicate Manager with this option.
n
Password for administrator@vsphere.local.
n
Host name or IP address of the Platform Services Controller if you are running on a vCenter Server
system with an external Platform Services Controller.
Procedure
1 Start vSphere Certicate Manager and select option 6.
2 Respond to the prompts.
vSphere Certicate Manager replaces all solution user certicates.
vSphere Security
88 VMware, Inc.