6.7

Table Of Contents
n
SubjectAltName must contain DNS Name=machine_FQDN
n
CRT format
n
Contains the following Key Usages: Digital Signature, Key Encipherment.
n
Client Authentication and Server Authentication cannot be present under Enhanced Key Usage.
VMCA does not support the following certificates.
n
Certificates with wildcards
n
The algorithms md2WithRSAEncryption 1.2.840.113549.1.1.2, md5WithRSAEncryption
1.2.840.113549.1.1.4, and sha1WithRSAEncryption 1.2.840.113549.1.1.5 are not recommended.
n
The algorithm RSASSA-PSS with OID 1.2.840.113549.1.1.10 is not supported.
Certificate Compliance to RFC 2253
The certificate must be in compliance with RFC 2253.
If you do not generate CSRs using Certificate Manager, ensure that the CSR includes the following fields.
String X.500 AttributeType
CN
commonName
L
localityName
ST
stateOrProvinceName
O
organizationName
OU
organizationalUnitName
C
countryName
STREET
streetAddress
DC
domainComponent
UID
userid
If you generate CSRs using Certificate Manager, you are prompted for the following information, and
Certificate Manager adds the corresponding fields to the CSR file.
n
The password of the administrator@vsphere.local user, or for the administrator of the vCenter Single
Sign-On domain that you are connecting to.
n
If you are generating a CSR in an environment with an external Platform Services Controller, you are
prompted for the host name or IP address of the Platform Services Controller.
n
Information that Certificate Manager stores in the certool.cfg file. For most fields, you can accept
the default or provide site-specific values. The FQDN of the machine is required.
n
Password for administrator@vsphere.local.
n
Two-letter country code
n
Company name
Platform Services Controller Administration
VMware, Inc. 74