6.5.1

Table Of Contents
These steps are not required for a mixed mode environment that includes vSphere 6.0 and vSphere 6.5
nodes. These steps are required only if:
n
Your environment includes both vCenter Single Sign-On 5.5 and vCenter Single Sign-On 6.x services.
n
The vCenter Single Sign-On services are set up to replicate vmdir data.
n
You plan to replace the default VMCA-signed certificates with custom certificates for the node on
which the vCenter Single Sign-On 6.x service runs.
Note Upgrading the complete environment before restarting the services is best practice. Replacing the
VMware Directory Service certificate is not usually recommended.
Procedure
1 On the node on which the vCenter Single Sign-On 5.5 service runs, set up the environment so the
vCenter Single Sign-On 6.x service is known.
a Back up all files C:\ProgramData\VMware\CIS\cfg\vmdird.
b Make a copy of the vmdircert.pem file on the 6.x node, and rename it to
<sso_node2.domain.com>.pem, where <sso_node2.domain.com> is the FQDN of the 6.x node.
c Copy the renamed certificate to C:\ProgramData\VMware\CIS\cfg\vmdird to replace the
existing replication certificate.
2 Restart the VMware Directory Service on all machines where you replaced certificates.
You can restart the service from the vSphere Web Client or use the service-control command.
Use VMCA as an Intermediate Certificate Authority
You can replace the VMCA root certificate with a third-party CA-signed certificate that includes VMCA in
the certificate chain. Going forward, all certificates that VMCA generates include the full chain. You can
replace existing certificates with newly generated certificates.
Procedure
1 Replace the Root Certificate (Intermediate CA)
The first step in replacing the VMCA certificates with custom certificates is generating a CSR,
sending the CSR to be signed. You then add the signed certificate to VMCA as a root certificate.
2 Replace Machine SSL Certificates (Intermediate CA)
After you have received the signed certificate from the CA and made it the VMCA root certificate,
you can replace all machine SSL certificates.
3 Replace Solution User Certificates (Intermediate CA)
After you replace the machine SSL certificates, you can replace the solution user certificates.
Platform Services Controller Administration
VMware, Inc. 133