6.7

Table Of Contents
Regenerate a New VMCA Root Certificate and Replace All
Certificates
You can regenerate the VMCA root certificate, and replace the local machine SSL certificate, and the
local solution user certificates with VMCA-signed certificates. In multi-node deployments, run vSphere
Certificate Manager with this option on the Platform Services Controller and then run the utility again on
all other nodes and select Replace Machine SSL certificate with VMCA Certificate and
Replace Solution user certificates with VMCA certificates.
When you replace the existing machine SSL certificate with a new VMCA-signed certificate, vSphere
Certificate Manager prompts you for information and enters all values, except for the password and the IP
address of the Platform Services Controller, into the certool.cfg file.
n
Password for administrator@vsphere.local.
n
Two-letter country code
n
Company name
n
Organization name
n
Organization unit
n
State
n
Locality
n
IP address (optional)
n
Email
n
Host name, that is, the fully qualified domain name of the machine for which you want to replace the
certificate. If the host name does not match the FQDN, certificate replacement does not complete
correctly and your environment might end up in an unstable state.
n
IP address of Platform Services Controller if you are running the command on a management node
Prerequisites
You must know the following information when you run vSphere Certificate Manager with this option.
n
Password for administrator@vsphere.local.
n
The FQDN of the machine for which you want to generate a new VMCA-signed certificate. All other
properties default to the predefined values but can be changed.
Procedure
1 Start vSphere Certificate Manager on an embedded deployment or on a Platform Services Controller.
2 Select option 4.
Platform Services Controller Administration
VMware, Inc. 101