6.0.3

Table Of Contents
n
If you are upgrading from a vSphere 5.x environment, you might have to replace the vCenter Single
Sign-On certicate inside vmdir. See “Replace the VMware Directory Service Certicate in Mixed Mode
Environments,” on page 101
Replace Solution User Certificates with Custom Certificates
When you select this option, vSphere Certicate Manager prompts you for replacement certicates for the
existing solution user certicates. In multi-node deployments, run vSphere Certicate Manager with this
option to replace the machine solution user certicate on the Platform Services Controller and the full set of
solution users on each management node.
Prerequisites
Before you start, you need a CSR for each machine in your environment. You can generate the CSR using
vSphere Certicate Manager or explicitly.
1 To generate the CSR using vSphere Certicate Manager, see “Generate Certicate Signing Requests
with vSphere Certicate Manager (Custom Certicates),” on page 89.
2 To generate the CSR explicitly, request a certicate for each solution user on each node from your third-
party or enterprise CA. The certicate must meet the following requirements:
n
Key size: 2048 bits or more (PEM encoded)
n
CRT format
n
x509 version 3
n
SubjectAltName must contain DNS Name=<machine_FQDN>
n
Each solution user certicate must have a dierent Subject. Consider, for example, including the
solution user name (such as vpxd) or other unique identier.
n
Contains the following Key Usages: Digital Signature, Non Repudiation, Key Encipherment
See also VMware Knowledge Base article 2112014, Obtaining vSphere certicates from a Microsoft
Certicate Authority.
Procedure
1 Start vSphere Certicate Manager and select option 5.
2 Select option 2 to start certicate replacement and respond to the prompts.
vSphere Certicate Manager prompts you for the following information:
n
Password for administrator@vsphere.local.
n
Certicate and key for machine solution user
n
If you run vSphere Certicate Manager on a Platform Services Controller node, you are prompted
for the certicate and key (vpxd.crt and vpxd.key) for the machine solution user.
n
If you run vSphere Certicate Manager on a management node or an embedded deployment, you
are prompted for the full set of certicates and keys (vpxd.crt and vpxd.key) for all solution users.
What to do next
Depending on your environment, you might have to replace additional certicates explicitly.
n
If company policy requires that you replace all certicates, replace the vmdir root certicate. See
“Replace the VMware Directory Service Certicate,” on page 110
n
If you are upgrading from a vSphere 5.x environment, you might have to replace the vCenter Single
Sign-On certicate inside vmdir. See “Replace the VMware Directory Service Certicate in Mixed Mode
Environments,” on page 101
Chapter 3 vSphere Security Certificates
VMware, Inc. 91