6.7

Table Of Contents
Replacement of Solution User Certificates in Environments with Multiple
Management Nodes
If your environment includes multiple management nodes and a single Platform Services Controller,
follow these steps for certificate replacement.
Note When you list solution user certificates in large deployments, the output of dir-cli list includes
all solution users from all nodes. Run vmafd-cli get-machine-id --server-name localhost to find
the local machine ID for each host. Each solution user name includes the machine ID.
vSphere Certificate
Manager
You run vSphere Certificate Manager on each machine. On management
nodes, you are prompted for the IP address of the
Platform Services Controller. Depending on the task you perform, you are
also prompted for certificate information.
Manual Certificate
Replacement
1 Generate or request a certificate. You need the following certificates:
n
A certificate for the machine solution user on the
Platform Services Controller.
n
A certificate for the machine solution user on each management
node.
n
A certificate for each of the following solution users on each
management node:
n
vpxd solution user
n
vpxd-extension solution user
n
vsphere-webclient solution user
2 Replace the certificates on each node. The precise process depends
on the type of certificate replacement that you are performing. See
Managing Certificates with the vSphere Certificate Manager Utility
See the following topics for details:
n
Replace Solution User Certificates With New VMCA-Signed Certificates
n
Replace Solution User Certificates (Intermediate CA)
n
Replace Solution User Certificates With Custom Certificates
Platform Services Controller Administration
VMware, Inc. 89