6.5.1

Table Of Contents
Procedure
1 To keep your current SSL certificates, back up the SSL certificates that are on the
vCenter Server Appliance system before you upgrade to vCenter Server Appliance 6.5.
The default location of the SSL certificates is %allusersprofile%\Application
Data\VMware\VMware VirtualCenter.
2 If you have Custom or Thumbprint certificates, see Host Upgrades and Certificates to determine your
preparatory steps.
3 Run vCenter Host Agent Pre-Upgrade Checker.
4 If you have vSphere HA clusters, SSL certificate checking must be enabled.
If certificate checking is not enabled when you upgrade, vSphere HA fails to configure on the hosts.
a Select the vCenter Server Appliance instance in the inventory panel.
b Select the Manage tab and the General subtab.
c Verify that the SSL settings field is set to vCenter Server requires verified host SSL
certificates.
Your ESXi hosts are ready for vCenter Server Appliance upgrade.
Host Upgrades and Certificates
If you upgrade an ESXi host to ESXi 6.0 or later, the upgrade process replaces the self-signed
(thumbprint) certificates with VMCA-signed certificates. If the ESXi host uses custom certificates, the
upgrade process retains those certificates even if those certificates are expired or invalid.
If you decide not to upgrade your hosts to ESXi 6.0 or later, the hosts retain the certificates that they are
currently using even if the host is managed by a vCenter Server system that uses VMCA certificates.
vSphere Upgrade
VMware, Inc. 62