6.5.1

Table Of Contents
Table 33. ESXi CSR Settings
Parameter Default Value Advanced Option
Key Size 2048 N.A.
Key Algorithm RSA N.A.
Certificate Signature Algorithm sha256WithRSAEncryption N.A.
Common Name Name of the host if the host was
added to vCenter Server by host
name.
IP address of the host if the host
was added to vCenter Server by
IP address.
N.A.
Country USA vpxd.certmgmt.certs.cn.country
Email address vmca@vmware.com vpxd.certmgmt.certs.cn.email
Locality (City) Palo Alto vpxd.certmgmt.certs.cn.localityName
Organization Unit Name VMware Engineering vpxd.certmgmt.certs.cn.organizationalUnitName
Organization Name VMware vpxd.certmgmt.certs.cn.organizationName
State or province California vpxd.certmgmt.certs.cn.state
Number of days the certificate is
valid.
1825 vpxd.certmgmt.certs.cn.daysValid
Hard threshold for certificate
expiration. vCenter Server raises a
red alarm when this threshold is
reached.
30 days vpxd.certmgmt.certs.cn.hardThreshold
Poll interval for vCenter Server
certificate validity checks.
5 days vpxd.certmgmt.certs.cn.pollIntervalDays
Soft Threshold for certificate
expiration. vCenter Server raises an
event when this threshold is
reached.
240 days vpxd.certmgmt.certs.cn.softThreshold
Mode that vCenter Server users to
determine whether existing
certificates are replaced. Change
this mode to retain custom
certificates during upgrade. See
Host Upgrades and Certificates.
Default is vmca
You can also specify thumbprint or
custom. See Change the
Certificate Mode.
vpxd.certmgmt.mode
Change Certificate Default Settings
When a host is added to a vCenter Server system, vCenter Server sends a Certificate Signing Request
(CSR) for the host to VMCA. You can change some of the default settings in the CSR using the
vCenter Server Advanced Settings in the vSphere Web Client.
Change company-specific default certificate settings. See ESXi Certificate Default Settings for a complete
list of default settings. Some of the defaults cannot be changed.
vSphere Security
VMware, Inc. 59