6.0.3

Table Of Contents
Replace All Certificates with Custom Certificate (Certificate Manager)
You can use the vSphere Certicate Manager utility to replace all certicates with custom certicates. Before
you start the process, you must send CSRs to your CA. You can use Certicate Manager to generate the
CSRs.
One option is to only replace the machine SSL certicate, and to use the solution user certicates that are
provisioned by VMCA. Solution user certicates are used only for communication between vSphere
Components.
When you use custom certicates, you are responsible for provisioning each node that you add to your
environment with custom certicates. VMCA still provisions with VMCA-signed certicates, and you are
responsible for replacing those certicates. You can use the vSphere Certicate Manager utility or use CLIs
for manual certicate replacement. Certicates are stored in VECS.
Generate Certificate Signing Requests with vSphere Certificate Manager (Custom
Certificates)
You can use vSphere Certicate Manager to generate Certicate Signing Requests (CSRs) that you can then
use with your enterprise CA or send to an external certicate authority. You can use the certicates with the
dierent supported certicate replacement processes.
You can run the Certicate Manager tool from the command line as follows:
Windows
C:\Program Files\VMware\vCenter Server\vmcad\certificate-manager.bat
Linux
/usr/lib/vmware-vmca/bin/certificate-manager
Prerequisites
vSphere Certicate Manager prompts you for information. The prompts depend on your environment and
on the type of certicate you want to replace.
n
For any CSR generation, you are prompted for the password of the administrator@vsphere.local user, or
for the administrator of the vCenter Single Sign-On domain that you are connecting to.
n
If you are generating a CSR in an environment with an external Platform Services Controller, you are
prompted for the host name or IP address of the Platform Services Controller.
n
To generate a CSR for a machine SSL certicate, you are prompted for certicate properties, which are
stored in the certool.cfg le. For most elds, you can accept the default or provide site-specic values.
The FQDN of the machine is required.
Procedure
1 On each machine in your environment, start vSphere Certicate Manager and select option 1.
2 Supply the password and the Platform Services Controller IP address or host name if prompted.
3 Select option 1 to generate the CSR, answer the prompts and exit Certicate Manager.
As part of the process, you have to provide a directory. Certicate Manager places the certicate and
key les in the directory.
4 If you also want to replace all solution user certicates, restart Certicate Manager.
5 Select option 5.
6 Supply the password and the Platform Services Controller IP address or host name if prompted.
Chapter 3 vSphere Security Certificates
VMware, Inc. 89