6.7

Table Of Contents
The recommended upgrade workflow depends on the current certificates.
Host Provisioned with
Thumbprint Certificates
If your host is currently using thumbprint certificates, it is automatically
assigned VMCA certificates as part of the upgrade process.
Note You cannot provision legacy hosts with VMCA certificates. You must
upgrade those hosts to ESXi 6.0 later.
Host Provisioned with
Custom Certificates
If your host is provisioned with custom certificates, usually third-party CA-
signed certificates, those certificates remain in place during upgrade.
Change the certificate mode to Custom to ensure that the certificates are
not replaced accidentally during a certificate refresh later.
Note If your environment is in VMCA mode, and you refresh the
certificates from the vSphere Web Client, any existing certificates are
replaced with certificates that are signed by VMCA.
Going forward, vCenter Server monitors the certificates and displays
information, for example, about certificate expiration, in the
vSphere Web Client.
Hosts Provisioned with
Auto Deploy
Hosts that are being provisioned by Auto Deploy are always assigned new
certificates when they are first booted with ESXi 6.0 or later software. When
you upgrade a host that is provisioned by Auto Deploy, the Auto Deploy
server generates a certificate signing request (CSR) for the host and
submits it to VMCA. VMCA stores the signed certificate for the host. When
the Auto Deploy server provisions the host, it retrieves the certificate from
VMCA and includes it as part of the provisioning process.
You can use Auto Deploy with custom certificates.
Change the Certificate Mode
Use VMCA to provision the ESXi hosts in your environment unless corporate policy requires that you use
custom certificates. To use custom certificates with a different root CA, you can edit the vCenter Server
vpxd.certmgmt.mode advanced option. After the change, the hosts are no longer automatically
provisioned with VMCA certificates when you refresh certificates. You are responsible for the certificate
management in your environment.
You can use the vCenter Server advanced settings to change to thumbprint mode or to custom CA mode.
Use thumbprint mode only as a fallback option.
Procedure
1 Select the vCenter Server that manages the hosts and click Configure.
2 Click Advanced Settings, and click Edit.
3 In the Filter box, enter certmgmt to display only certificate management keys.
vCenter Server Upgrade
VMware, Inc. 86