6.5.1

Table Of Contents
View Certificate Details for a Single ESXi Host
For ESXi 6.0 and later hosts that are in VMCA mode or custom mode, you can view certificate details
from the vSphere Web Client. The information about the certificate can be helpful for debugging.
Procedure
1 Browse to the host in the vSphere Web Client inventory.
2 Select Configure.
3 Under System, click Certificate.
You can examine the following information. This information is available only in the single-host view.
Field Description
Subject The subject used during certificate generation.
Issuer The issuer of the certificate.
Valid From Date on which the certificate was generated.
Valid To Date on which the certificate expires.
Status Status of the certificate, one of the following.
Good Normal operation.
Expiring Certificate will expire soon.
Expiring shortly Certificate is 8 months or less away from expiration
(Default).
Expiration
imminent
Certificate is 2 months or less away from expiration
(Default).
Expired Certificate is not valid because it expired.
Renew or Refresh ESXi Certificates
If VMCA assigns certificates to your ESXi hosts (6.0 and later), you can renew those certificates from the
vSphere Web Client. You can also refresh all certificates from the TRUSTED_ROOTS store associated
with vCenter Server.
You can renew your certificates when they are about to expire, or if you want to provision the host with a
new certificate for other reasons. If the certificate is already expired, you must disconnect the host and
reconnect it.
By default, vCenter Server renews the certificates of a host with status Expired, Expiring immediately, or
Expiring each time the host is added to the inventory, or reconnected.
Procedure
1 Browse to the host in the vSphere Web Client inventory.
2 Select Configure.
vSphere Security
VMware, Inc. 61