6.5.1

Table Of Contents
n
PEM format. VMware supports PKCS8 and PKCS1 (RSA keys). When keys are added to VECS, they
are converted to PKCS8
n
x509 version 3
n
For root certificates, the CA extension must be set to true, and the cert sign must be in the list of
requirements.
n
SubjectAltName must contain DNS Name=<machine_FQDN>
n
CRT format
n
Contains the following Key Usages: Digital Signature, Non Repudiation, Key Encipherment
n
Start time of one day before the current time
n
CN (and SubjectAltName) set to the host name (or IP address) that the ESXi host has in the
vCenter Server inventory.
Procedure
1 Send CSRs for the following certificates to your enterprise or third-party certificate provider.
n
A machine SSL certificate for each machine. For the machine SSL certificate, the
SubjectAltName field must contain the fully qualified domain name (DNS
NAME=machine_FQDN)
n
Optionally, four solution user certificates for each embedded system or management node.
Solution user certificates should not include IP address, host name, or email address. Each
certificate must have a different certificate Subject.
n
Optionally, a machine solution user certificate for external Platform Services Controller instances.
This certificate differs from the machine SSL certificate for the Platform Services Controller.
Typically, the result is a PEM file for the trusted chain, plus the signed SSL certificates for each
Platform Services Controller or management node.
2 List the TRUSTED_ROOTS and machine SSL stores.
vecs-cli store list
a Ensure that the current root certificate and all machine SSL certificates are signed by VMCA.
b Note down the Serial number, issuer, and Subject CN fields.
c (Optional) With a Web browser, open a HTTPS connection to a node where the certificate will be
replaced, check the certificate information, and ensure that it matches the machine SSL
certificate.
Platform Services Controller Administration
VMware, Inc. 147