6.5.1

Table Of Contents
4 Run the following command to enable client authentication.
camconfig ssl-cliAuth -e
Going forward, vSphere Authentication Proxy checks the certificate of each host that is added.
5 If you later want to disable client authentication again, run the following command.
camconfig ssl-cliAuth -n
Import the vSphere Authentication Proxy Certificate to ESXi Host
By default, ESXi hosts require explicit verification of the vSphere Authentication Proxy certificate. If you
are using vSphere Auto Deploy, the Auto Deploy service takes care of adding the certificate to hosts that
it provisions. For other hosts, you have to add the certificate explicitly.
Prerequisites
n
Upload the vSphere Authentication Proxy certificate to the ESXi host. You can find the certificate in
the following location.
vCenter Server
Appliance
/var/lib/vmware/vmcam/ssl/rui.crt
vCenter Server
Windows
C:\ProgramData\VMware\vCenterServer\data\vmcamd\ssl\rui.c
rt
n
Verify that the UserVars.ActiveDirectoryVerifyCAMCertificate ESXi advanced setting is set to
1 (the default).
Procedure
1 In the vSphere Web Client, select the ESXi host and click Configure.
2 Under System, select Authentication Services.
3 Click Import Certificate.
4 Type the certificate file path following the format [datastore]/path/certname.crt, and click OK.
Generate a New Certificate for vSphere Authentication Proxy
If you want to generate a new certificate that is provisioned by VMCA, or a new certificate that includes
VMCA as a subordinate certificate, follow the steps in this topic.
See Set Up vSphere Authentication Proxy to Use Custom Certificates if you want to use a custom
certificate that is signed by a third-party or enterprise CA.
Prerequisites
You must have root or Administrator privileges on the system on which vSphere Authentication Proxy is
running.
vSphere Security
VMware, Inc. 95