5.8

Table Of Contents
5 (Optional) To enforce verification of certificate validity, select the Accept only SSL certificates
signed by a trusted Certificate Authority check box.
See vSphere Replication Certificate Verification for details of how vSphere Replication handles
certificates.
6 Generate or install a new SSL certificate.
Option Action
Generate a self-signed certificate Click Generate and Install. Using a self-signed certificate provides trust by
thumbprint only and might not be suitable for environments that require high
levels of security. You cannot use a self-signed certificate if you selected Accept
only SSL certificates signed by a trusted Certificate Authority.
Upload a certificate Click Browse to select a PKCS#12 certificate and click Upload and Install.
Public key certificates must meet certain requirements. See Requirements When
Using a Public Key Certificate with vSphere Replication.
7 Click Save and Restart Service to apply the changes.
You changed the SSL certificate and optionally changed the security policy to use trust by validity and
certificates signed by a certificate authority.
Note If you change a certificate on one of the source or target sites, its status changes to Connection
issue. You can reconnect the source and target sites manually. Alternatively, the sites reconnect when
you run an operation between them.
vSphere Replication Certificate Verification
vSphere Replication verifies the certificates of vCenter Server and remote vSphere Replication servers.
All communication between vCenter Server, the local vSphere Replication appliance, and the remote
vSphere Replication appliance goes through a vCenter Server proxy at port 80. All SSL traffic is
tunnelled.
VMware vSphere Replication Administration
VMware, Inc. 41