VMware vCenter 7.x
VMware vCenter 8.x
VMware vCenter 9.x
openssl s_client -showcerts -connect dc.domain.com:636 </dev/null 2>/dev/null|openssl x509 -outform PEMCertificate chain
0 s:/CN=DC.example.comi:/DC=com/DC=example/CN=###-CA-----BEGIN CERTIFICATE-----##############################################################.............snip.............-----END CERTIFICATE-----1 s:/DC=com/DC=example/CN=###-CAi:/CN=###-ROOT-CA-----BEGIN CERTIFICATE-----##############################################################.............snip.............##############################################################
-----END CERTIFICATE----------BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines for the certificate.If this is an ELM (Enhanced Linked Mode) environment, only perform the following steps on a single vCenter, as the IdP configurations replicate to the other linked vCenter servers.
Take the appropriate snapshot(s) of vCenter Server.
Note: If Enhanced Linked Mode, make sure to take offline snapshots of all linked vCenter virtual machines before proceeding.
Log in to the vSphere Client using a Single Sign On Administrator.
Under Menu, select Administration > Configuration > Identity Sources.
Important Information about configuring an LDAPS identity source: