6.5.1

Table Of Contents
Make VMCA an Intermediate Certificate Authority from the
Platform Services Controller Web Interface
You can have the VMCA certificate signed by another CA so that VMCA becomes an intermediate CA.
Going forward, all certificates that VMCA generates include the full chain.
You can perform this setup by using the vSphere Certificate Manager utility, by using CLIs, or from the
Platform Services Controller Web interface.
Prerequisites
1 Generate the CSR.
2 Edit the certificate that you receive, and place the current VMCA root certificate at the bottom.
Generate CSR with vSphere Certificate Manager and Prepare Root Certificate (Intermediate CA) explains
both steps.
Procedure
1 From a Web browser, connect to the vSphere Web Client or the Platform Services Controller.
Option Description
vSphere Web Client
https://vc_hostname_or_IP/vsphere-client
Platform Services Controller
https://psc_hostname_or_IP/psc
In an embedded deployment, the Platform Services Controller host name or IP
address is the same as the vCenter Server host name or IP address.
2 Specify the user name and password for administrator@vsphere.local or another member of the
vCenter Single Sign-On Administrators group.
If you specified a different domain during installation, log in as administrator@mydomain.
3 To replace the existing certificate with the chained certificate, follow these steps:
a Under Certificates, click Certificate Authority and select the Root Certificate tab.
b Click Replace Certificate, add the private key file and the certificate file (full chain), and click OK.
c In the Replace Root Certificate dialog box, click Browse and select the private key, click
Browse again and select the certificate, and click OK.
Going forward, VMCA signs all certificates that it issues with the new chained root certificate.
4 Renew the machine SSL certificate for the local system.
a Under Certificates, click Certificate Management and click the Machine Certificates tab.
b Select the certificate, click Renew, and answer Yes to the prompt.
VMCA replaces the machine SSL certificate with the certificate that is signed by the new CA.
Platform Services Controller Administration
VMware, Inc. 99