After Renewing Certificate via Web Browser Validity Period Becomes 10 Years
search cancel

After Renewing Certificate via Web Browser Validity Period Becomes 10 Years

book

Article ID: 334889

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

Symptoms:

The validity period certificates were 2 years on vCenter Server 6.5 Update 2 or later, however, when you renew or replace certificates through Web Browser using below steps, validity period will be 10 years.

 

  • Connect to the VC or PSC from web browser
  • Navigate to Certificate Manager.
  • Click on "Machine Certificate" and then click "Renew."

 

 

Environment

VMware vCenter Server 6.x, 7.x and 8.x

Resolution

This issue is resolved in vCenter Server 6.5 U3 and later.

Workaround:

The validity period of all certificates issued by the VMware Certificate Authority (VMCA) is reduced to 2 years

The default validity period of the certificates issued by VMCA was 10 years. According to the CA/Browser Forum recommendations, certificates issued after March 1, 2018 must have a validity period no greater than 825 days or 2 years.