6.7

Table Of Contents
Certificate Replacement in Environments That Include External Solutions
Some solutions, such as VMware vCenter Site Recovery Manager or VMware vSphere Replication, are
always installed on a different machine than the vCenter Server system or Platform Services Controller. If
you replace the default machine SSL certificate on the vCenter Server system or the
Platform Services Controller, a connection error results if the solution attempts to connect to the
vCenter Server system.
You can run the ls_update_certs script to resolve the issue. See VMware Knowledge Base article
2109074 for details.
Managing Certificates with the vSphere Client
You can view and manage certificates by using the vSphere Client. You also can perform many certificate
management tasks with the vSphere Certificate Manager utility.
The vSphere Client enables you to perform these management tasks.
n
View the trusted root certificates and SSL certificates.
n
Renew existing certificates or replace certificates.
Most parts of the certificate replacement workflows are supported fully from the vSphere Client. For
generating CSRs, you can use the vSphere Certificate Manage utility.
Supported Workflows
After you install a Platform Services Controller, the VMware Certificate Authority on that node provisions
all other nodes in the environment with certificates by default. See Chapter 3 vSphere Security
Certificates for recommendations on the current recommendations for managing certificates.
Platform Services Controller Administration
VMware, Inc. 90