This article provides steps to identify the expiry date of the VMware STS certificate.
Notes:
Here are the scenarios where STS signing certificate is expected to have a lifetime of around 2 years.
Important: In vCenter Server version 7.0 U1, you receive a weekly notification when the vCenter Single Sign-On Security Token Service (STS) signing certificate is close to expiration. Notifications start 90 days before the STS certificate expires and turn into daily over the last week before expiration.
To verify the expiry date of your VMware Security Token Service (STS):
Note: Available from vCenter Server 7.0 Update2 and later.
https://vcenter_server_ip_address_or_fqdn/ui
.chsh -s /bin/bash root
(per Connecting to vCenter Server Virtual Appliance using WinSCP fails with the error: Received too large (1433299822 B) SFTP packet. Max supported packet size is 1024000 B) cd /tmp
python checksts.py
.Important: The certificate expiry alarm does not account for the STS certificate. There is a separate alarm for the STS certificate status. The only method to determine the expiry date of the STS certificate is in the resolution of this article. VMware recommends occasionally check the STS certificate to ensure it does not expire. For additional information, see VMware's vSphere blog:
Signing Certificate is Not Valid – Security Token Service Certificate Issue in vSphere.
Main certificates article: For more information on Status Alarms for certificates, see CertificateStatusAlarm - There are certificate that expired or about to expire / Certificate Status Change Alarm Triggered on VMware vCenter Server.
VMware Skyline Health Diagnostics for vSphere - FAQ
Error "503 Service Unavailable" when attempting to access vCenter Server vSphere Client