6.5.1

Table Of Contents
If you generate CSRs using Certificate Manager, you are prompted for the following information, and
Certificate Manager adds the corresponding fields to the CSR file.
n
The password of the administrator@vsphere.local user, or for the administrator of the vCenter Single
Sign-On domain that you are connecting to.
n
If you are generating a CSR in an environment with an external Platform Services Controller, you are
prompted for the host name or IP address of the Platform Services Controller.
n
Information that Certificate Manager stores in the certool.cfg file. For most fields, you can accept
the default or provide site-specific values. The FQDN of the machine is required.
n
Password for administrator@vsphere.local.
n
Two-letter country code
n
Company name
n
Organization name
n
Organization unit
n
State
n
Locality
n
IP address (optional)
n
Email
n
Host name, that is, the fully qualified domain name of the machine for which you want to replace
the certificate. If the host name does not match the FQDN, certificate replacement does not
complete correctly and your environment might end up in an unstable state.
n
IP address of Platform Services Controller if you are running the command on a vCenter Server
(management) node
Requirements When Using VMCA as an Intermediate CA
When you use VMCA as an intermediate CA, the certificates must meet the following requirements.
Platform Services Controller Administration
VMware, Inc. 81