6.5.1

Table Of Contents
Certificate Requirements for Dierent Solution Paths
Certificate requirements depend on whether you use VMCA as an intermediate CA or you use custom
certificates. Requirements are also different for machine certificates and for solution user certificates.
Before you begin, ensure that all nodes in your environment are time synchronized.
Requirements for All Imported Certificates
n
Key size: 2048 bits or more (PEM encoded)
n
PEM format. VMware supports PKCS8 and PKCS1 (RSA keys). When you add keys to VECS, they
are converted to PKCS8.
n
x509 version 3
n
SubjectAltName must contain DNS Name=machine_FQDN
n
CRT format
n
Contains the following Key Usages: Digital Signature, Key Encipherment.
n
Client Authentication and Server Authentication cannot be present under Enhanced Key Usage.
VMCA does not support the following certificates.
n
Certificates with wildcards
n
The algorithms md2WithRSAEncryption 1.2.840.113549.1.1.2, md5WithRSAEncryption
1.2.840.113549.1.1.4, and sha1WithRSAEncryption 1.2.840.113549.1.1.5 are not recommended.
n
The algorithm RSASSA-PSS with OID 1.2.840.113549.1.1.10 is not supported.
Certificate Compliance to RFC 2253
The certificate must be in compliance with RFC 2253.
If you do not generate CSRs using Certificate Manager, ensure that the CSR includes the following fields.
String X.500 AttributeType
CN
commonName
L
localityName
ST
stateOrProvinceName
O
organizationName
OU
organizationalUnitName
C
countryName
STREET
streetAddress
DC
domainComponent
UID
userid
Platform Services Controller Administration
VMware, Inc. 80