6.0.3

Table Of Contents
7 Select option 1 to generate the CSRs, answer the prompts and exit Certicate Manager.
As part of the process, you have to provide a directory. Certicate Manager places the certicate and
key les in the directory.
On each Platform Services Controller node, Certicate Manager generates one certicate and key pair.
On each vCenter Server node, Certicate Manager generates four certicate and key pairs.
What to do next
Perform certicate replacement.
Replace Machine SSL Certificate with Custom Certificate
The machine SSL certicate is used by the reverse proxy service on every management node,
Platform Services Controller, and embedded deployment. Each machine must have a machine SSL certicate
for secure communication with other services. You can replace the certicate on each node with a custom
certicate.
Prerequisites
Before you start, you need a CSR for each machine in your environment. You can generate the CSR using
vSphere Certicate Manager or explicitly.
1 To generate the CSR using vSphere Certicate Manager, see “Generate Certicate Signing Requests
with vSphere Certicate Manager (Custom Certicates),” on page 89.
2 To generate the CSR explicitly, request a certicate for each machine from your third-party or enterprise
CA. The certicate must meet the following requirements:
n
Key size: 2048 bits or more (PEM encoded)
n
CRT format
n
x509 version 3
n
SubjectAltName must contain DNS Name=<machine_FQDN>
n
Contains the following Key Usages: Digital Signature, Non Repudiation, Key Encipherment
See also VMware Knowledge Base article 2112014, Obtaining vSphere certicates from a Microsoft
Certicate Authority.
Procedure
1 Start vSphere Certicate Manager and select option 1.
2 Select option 2 to start certicate replacement and respond to the prompts.
vSphere Certicate Manager prompts you for the following information:
n
Password for administrator@vsphere.local.
n
Valid Machine SSL custom certicate (.crt le).
n
Valid Machine SSL custom key (.key le).
n
Valid signing certicate for the custom machine SSL certicate (.crt le).
n
If you are running the command on a management node in a multi-node deployment, IP address of
the Platform Services Controller.
What to do next
Depending on your environment, you might have to replace additional certicates explicitly.
n
If company policy requires that you replace all certicates, replace the vmdir root certicate. See
“Replace the VMware Directory Service Certicate,” on page 110
vSphere Security
90 VMware, Inc.