6.5.1

Table Of Contents
Switching from Thumbprint Mode to VMCA Mode
If you use thumbprint mode and you want to start using VMCA-signed certificates, the switch requires
some planning. The recommended workflow is as follows.
1 Remove all hosts from the vCenter Server system.
2 Switch to VMCA certificate mode. See Change the Certificate Mode.
3 Add the hosts to the vCenter Server system.
Note Any other workflow for this mode switch might result in unpredictable behavior.
Switching from Custom CA Mode to Thumbprint Mode
If you are encountering problems with your custom CA, consider switching to thumbprint mode
temporarily. The switch works seamlessly if you follow the instructions in Change the Certificate Mode.
After the mode switch, the vCenter Server system checks only the format of the certificate and no longer
checks the validity of the certificate itself.
Switching from Thumbprint Mode to Custom CA Mode
If you set your environment to thumbprint mode during troubleshooting, and you want to start using
custom CA mode, you must first generate the required certificates. The recommended workflow is as
follows.
1 Remove all hosts from the vCenter Server system.
2 Add the custom CA root certificate to TRUSTED_ROOTS store on VECS on the vCenter Server
system. See Update the vCenter Server TRUSTED_ROOTS Store (Custom Certificates).
3 For each ESXi host:
a Deploy the custom CA certificate and key.
b Restart services on the host.
4 Switch to custom mode. See Change the Certificate Mode.
5 Add the hosts to the vCenter Server system.
ESXi Certificate Default Settings
When a host is added to a vCenter Server system, vCenter Server sends a Certificate Signing Request
(CSR) for the host to VMCA. Most of the default values are well suited for many situations, but company-
specific information can be changed.
You can change many of the default settings using the vSphere Web Client. Consider changing the
organization, and location information. See Change Certificate Default Settings.
vSphere Security
VMware, Inc. 58