6.5.1

Table Of Contents
Reset All Certificates
Use the Reset All Certificates option if you want to replace all existing vCenter certificates with
certificates that are signed by VMCA.
When you use this option, you overwrite all custom certificates that are currently in VECS.
n
On a Platform Services Controller node, vSphere Certificate Manager can regenerate the root
certificate and replace the machine SSL certificate and the machine solution user certificate.
n
On a management node, vSphere Certificate Manager can replace the machine SSL certificate and
all solution user certificates.
n
In an embedded deployment, vSphere Certificate Manager can replace all certificates.
Which certificates are replaced depends on which options you select.
Manual Certificate Replacement
For some special cases, for example, if you want to replace only one type of solution user certificate, you
cannot use the vSphere Certificate Manager utility. In that case, you can use the CLIs included with your
installation for certificate replacement.
Understanding Stopping and Starting of Services
For certain parts of manual certificate replacement, you must stop all services and then start only the
services that manage the certificate infrastructure. If you stop services only when needed, you can
minimize downtime.
You have to stop and start services as part of the certificate replacement process.
n
If your environment uses an embedded Platform Services Controller, you start and stop all services,
as discussed in this document.
n
If your environment uses an external Platform Services Controller, you do not have to stop and start
VMware Directory Service (vmdird) and VMware Certificate Authority (vmcad) on the vCenter Server
node. Those services run on the Platform Services Controller.
Follow these rules of thumb.
n
Do not stop services to generate new public/private key pairs or new certificates.
n
If you are the only administrator, you do not have to stop services when you add a new root
certificate. The old root certificate remains available, and all services can still authenticate with that
certificate. Stop and immediately restart all services after you add the root certificate to avoid
problems with your hosts.
n
If your environment includes multiple administrators, stop services before you add a new root
certificate and restart services after you add a new certificate.
Platform Services Controller Administration
VMware, Inc. 120