6.5.1

Table Of Contents
Certificate Type Certificate Requirements
Machine SSL certificate The machine SSL certificate on each node must have a
separate certificate from your third-party or enterprise CA.
n
You can generate the CSRs using vSphere Certificate
Manager or create the CSR manually. The CSR must meet
the requirements listed under Requirements for All Imported
Certificates above.
n
If you use vSphere Certificate Manager, the tool prompts
you for certificate information for each solution user.
vSphere Certificate Manager stores the information in
certool.cfg. See Information that Certificate Manager
Prompts For.
n
For most fields, you can accept the default or provide site-
specific values. The FQDN of the machine is required.
Solution user certificate Each solution user on each node must have a separate
certificate from your third-party or enterprise CA.
n
You can generate the CSRs using vSphere Certificate
Manager or prepare the CSR yourself. The CSR must meet
the requirements listed under Requirements for All Imported
Certificates above.
n
If you use vSphere Certificate Manager, The tool prompts
you for certificate information for each solution user.
vSphere Certificate Manager stores the information in
certool.cfg. See Information that Certificate Manager
Prompts For.
Note You must use a different value for Name for each
solution user. If you generate the certificate manually, this
might show up as CN under Subject, depending on the tool
you use.
When later you replace solution user certificates with custom
certificates, provide the complete signing certificate chain of the
third-party CA.
Note Do not use CRL Distribution Points, Authority Information Access, or Certificate Template
Information in any custom certificates.
Platform Services Controller Administration
VMware, Inc. 83