6.7

Table Of Contents
3 Under System, click Certificate.
You can view detailed information about the selected host's certificate.
4 Click Renew or Refresh CA Certificates.
Option Description
Renew Retrieves a fresh signed certificate for the host from VMCA.
Refresh CA Certificates Pushes all certificates in the TRUSTED_ROOTS store in the vCenter Server
VECS store to the host.
5 Click Yes to confirm.
Change the Certificate Mode
Use VMCA to provision the ESXi hosts in your environment unless corporate policy requires that you use
custom certificates. To use custom certificates with a different root CA, you can edit the vCenter Server
vpxd.certmgmt.mode advanced option. After the change, the hosts are no longer automatically
provisioned with VMCA certificates when you refresh certificates. You are responsible for the certificate
management in your environment.
You can use the vCenter Server advanced settings to change to thumbprint mode or to custom CA mode.
Use thumbprint mode only as a fallback option.
Procedure
1 Select the vCenter Server that manages the hosts and click Configure.
2 Click Advanced Settings, and click Edit.
3 In the Filter box, enter certmgmt to display only certificate management keys.
4 Change the value of vpxd.certmgmt.mode to custom if you intend to manage your own certificates,
and to thumbprint if you temporarily want to use thumbprint mode, and click OK.
5 Restart the vCenter Server service.
Replacing ESXi SSL Certificates and Keys
Your company's security policy might require that you replace the default ESXi SSL certificate with a third-
party CA-signed certificate on each host.
By default, vSphere components use the VMCA-signed certificate and key that are created during
installation. If you accidentally delete the VMCA-signed certificate, remove the host from its
vCenter Server system, and add it back. When you add the host, vCenter Server requests a new
certificate from VMCA and provisions the host with it.
Replace VMCA-signed certificates with certificates from a trusted CA, either a commercial CA or an
organizational CA, if your company policy requires it.
vSphere Security
VMware, Inc. 60