6.7

Table Of Contents
Option Description
--password <admin_password>
Password of the administrator user. If you do not specify the
password, you are prompted.
--chain
Specify this option if you are publishing a chained certificate. No
option value is needed.
dir-cli trustedcert unpublish
Unpublishes a trusted root certificate currently in vmdir. Use this command, for example, if you added a
different root certificate to vmdir that is now the root certificate for all other certificates in your
environment. Unpublishing certificates that are no longer in use is part of hardening your environment.
Option Description
--cert-file <file>
Path to the certificate file to unpublish
--login <admin_user_id>
The administrator of the local vCenter Single Sign-On domain,
administrator@vsphere.local by default.
--password <admin_password>
Password of the administrator user. If you do not specify the
password, you are prompted.
dir-cli trustedcert list
Lists all trusted root certificates and their corresponding IDs. You need the certificate IDs to retrieve a
certificate with dir-cli trustedcert get.
Option Description
--login <admin_user_id>
The administrator of the local vCenter Single Sign-On domain,
administrator@vsphere.local by default.
--password <admin_password>
Password of the administrator user. If you do not specify the
password, you are prompted.
dir-cli trustedcert get
Retrieves a trusted root certificate from vmdir and writes it to a specified file.
Option Description
--id <cert_ID>
ID of the certificate to retrieve. The dir-cli trustedcert
list command shows the ID.
--outcert <path>
Path to write the certificate file to.
--outcrl <path>
Path to write the CRL file to. Not currently used.
--login <admin_user_id>
The administrator of the local vCenter Single Sign-On domain,
administrator@vsphere.local by default.
--password <admin_password>
Password of the administrator user. If you do not specify the
password, you are prompted.
Platform Services Controller Administration
VMware, Inc. 167