6.5.1

Table Of Contents
Procedure
1 In the vSphere Web Client, select the vCenter Server system that manages the hosts.
2 Click Configure, and click Advanced Settings.
3 In the Filter box, enter certmgmt to display only certificate management parameters.
4 Change the value of the existing parameters to follow company policy and click OK.
The next time you add a host to vCenter Server, the new settings are used in the CSR that
vCenter Server sends to VMCA and in the certificate that is assigned to the host.
What to do next
Changes to certificate metadata only affect new certificates. If you want to change the certificates of hosts
that are already managed by the vCenter Server system, you can disconnect and reconnect the hosts or
renew the certificates.
View Certificate Expiration Information for Multiple ESXi Hosts
If you are using ESXi 6.0 and later, you can view the certificate status of all hosts that are managed by
your vCenter Server system. The display allows you to determine whether any of the certificates expire
soon.
You can view certificate status information for hosts that are using VMCA mode and for hosts that are
using custom mode in the vSphere Web Client. You cannot view certificate status information for hosts in
thumbprint mode.
Procedure
1 Browse to the host in the vSphere Web Client inventory hierarchy.
By default, the Hosts display does not include the certificate status.
2 Right-click the Name field and select Show/Hide Columns.
3 Select Certificate Valid To, click OK, and scroll to the right if necessary.
The certificate information displays when the certificate expires.
If a host is added to vCenter Server or reconnected after a disconnect, vCenter Server renews the
certificate if the status is Expired, Expiring, Expiring shortly, or Expiration imminent. The status is
Expiring if the certificate is valid for less than eight months, Expiring shortly if the certificate is valid for
less than two months, and Expiration imminent if the certificate is valid for less than one month.
4 (Optional) Deselect other columns to make it easier to see what you are interested in.
What to do next
Renew the certificates that are about to expire. See Renew or Refresh ESXi Certificates.
vSphere Security
VMware, Inc. 60