6.2

Table Of Contents
Table 91. Registration Requirements
Updated Certificate
Register new certificate
with Identity Appliance
Register new certificate
with vRealize Appliance
Register new certificate with
IaaS
Identity Appliance Not applicable Done automatically when you
replace the vRealize
Appliance certificate
Done automatically when you
replace the vRealize Appliance
certificate
vRealize Appliance No Not applicable Yes
IaaS No Yes Not applicable
Note If your certificate uses a passphrase for encryption and you do not enter it when you replace your
certificate on the virtual appliance, the certificate replacement fails and the message Unable to load
private key appears.
In addition to certificates for the Identity Appliance, the vRealize Appliance, IaaS Website components,
and Manager Service components, your deployment can have certificates for the Identity Appliance
management site and the vRealize Appliance management site. Management Agents also have
certificates. Each IaaS machine runs a Management Agent.
For important information about troubleshooting, supportability, and trust requirements for certificates, see
the VMware knowledge base article at http://kb.vmware.com/kb/2106583.
This chapter includes the following topics:
n
Extracting Certificates and Private Keys
n
Updating the Identity Appliance Certificate
n
Updating the vRealize Appliance Certificate
n
Updating the IaaS Certificate
n
Replace the Identity Appliance Management Site Certificate
n
Updating the vRealize Appliance Management Site Certificate
n
Replace a Management Agent Certificate
Extracting Certificates and Private Keys
Certificates that you use with the virtual appliances must be in the PEM file format.
The examples in the following table use Gnu openssl commands to extract the certificate information you
need to configure the virtual appliances.
Installation and Configuration
VMware, Inc. 150