6.0.3

Table Of Contents
Manual Certificate Replacement
For some special cases, for example, if you want to replace only one type of solution user certicate, you
cannot use the vSphere Certicate Manager utility. In that case, you can use the CLIs included with your
installation for certicate replacement.
Understanding Starting and Stopping of Services
For certain parts of manual certicate replacement, you must stop all services and then start only the
services that manage the certicate infrastructure. If you stop services only when needed, you can minimize
downtime.
Follow these rules of thumb.
n
Do not stop services to generate new public/private key pairs or new certicates.
n
If you are the only administrator, you do not have to stop services when you add a new root certicate.
The old root certicate remains available, and all services can still authenticate with that certicate. Stop
and immediately restart all services after you add the root certicate to avoid problems with your hosts.
n
If your environment includes multiple administrators, stop services before you add a new root
certicate and restart services after you add a new certicate.
n
Stop services right before you perform these tasks:
n
Delete a machine SSL certicate or any solution user certicate in VECS.
n
Replace a solution user certicate in vmdir (VMware Directory Service).
Replace Existing VMCA-Signed Certificates With New VMCA-Signed Certificates
If the VMCA root certicate expires in the near future, or if you want to replace it for other reasons, you can
generate a new root certicate and add it to the VMware Directory Service. You can then generate new
machine SSL certicates and solution user certicates using the new root certicate.
Use the vSphere Certicate Manager utility to replace certicates for most cases.
If you need ne-grained control, this scenario gives detailed step-by-step instructions for replacing the
complete set of certicates using CLI commands. You can instead replace only individual certicates using
the procedure in the corresponding task.
Prerequisites
Only administrator@vsphere.local or other users in the CAAdmins group can perform certicate
management tasks. See Add Members to a vCenter Single Sign-On Group,” on page 57.
Procedure
1 Generate a New VMCA-Signed Root Certicate on page 93
You generate new VMCA-signed certicates with the certool CLI and publish them to vmdir.
2 Replace Machine SSL Certicates with VMCA-Signed Certicates on page 94
After you generate a new VMCA-signed root certicate, you can replace all machine SSL certicates in
your environment.
3 Replace Solution User Certicates With New VMCA-Signed Certicates on page 97
After you replace the machine SSL certicates, you can replace all solution user certicates. Solution
user certicates must be valid, that is, not expired, but none of the other information in the certicate is
used by the certicate infrastructure.
vSphere Security
92 VMware, Inc.