6.5.1

Table Of Contents
Procedure
1 Start vSphere Certificate Manager and select option 1.
2 Select option 2 to start certificate replacement and respond to the prompts.
vSphere Certificate Manager prompts you for the following information:
n
Password for administrator@vsphere.local.
n
Valid Machine SSL custom certificate (.crt file).
n
Valid Machine SSL custom key (.key file).
n
Valid signing certificate for the custom machine SSL certificate (.crt file).
n
If you are running the command on a management node in a multi-node deployment, IP address
of the Platform Services Controller.
What to do next
If you are upgrading from a vSphere 5.x environment, you might have to replace the vCenter Single Sign-
On certificate inside vmdir. See Replace the VMware Directory Service Certificate in Mixed Mode
Environments.
Replace Solution User Certificates with Custom Certificates
Many companies only require that you replace certificates of services that are accessible externally.
However, Certificate Manager also supports replacing solution user certificates. Solution users are
collections of services, for example, all services that are associated with the vSphere Web Client In multi-
node deployments replace the machine solution user certificate on the Platform Services Controller and
the full set of solution users on each management node.
When you are prompted for a solution user certificate, provide the complete signing certificate chain of
the third-party CA.
The format should be similar to the following.
-----BEGIN CERTIFICATE-----
Signing certificate
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
CA intermediate certificates
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
Root certificate of enterprise or external CA
-----END CERTIFICATE-----
Prerequisites
Before you start, you need a CSR for each machine in your environment. You can generate the CSR
using vSphere Certificate Manager or explicitly.
1 To generate the CSR using vSphere Certificate Manager, see Generate Certificate Signing Requests
with vSphere Certificate Manager (Custom Certificates).
Platform Services Controller Administration
VMware, Inc. 118