/opt/vmware/sddc-support/sos --certificate-health
VMware Cloud Foundation 4.x
VMware Cloud Foundation 5.x
openssl req -new -newkey rsa:2048 -nodes -keyout sddc.key -out sddc.csr
mkdir /tmp/certs
[ req ]
req_extensions = v3_req
[ v3_req ]
extendedKeyUsage = serverAuth, clientAuth
authorityKeyIdentifier=keyid,issuer
authorityInfoAccess = caIssuers;URI:https://sddc-manager.example.com/afd/vecs/ca
openssl x509 -req -days 3650 -in sddc-manager.example.com.csr -out sddc-manager.example.com.crt -CA /var/lib/vmware/vmca/root.cer -CAkey /var/lib/vmware/vmca/privatekey.pem -extensions v3_req -CAcreateserial -extfile cert.cfg
cat sddc-manager.example.com.crt>>sddc-manager.example.com.pem
cat /var/lib/vmware/vmca/root.cer>>sddc-manager.example.com.pem
cp /etc/ssl/private/vcf_https.key /etc/ssl/private/old_vcf_https.key
cp /etc/ssl/certs/vcf_https.crt /etc/ssl/certs/old_vcf_https.crt
rm /etc/ssl/certs/vcf_https.crt
mv /home/vcf/sddc-manager.example.com.pem /etc/ssl/certs/vcf_https.crt
mv /home/vcf/sddc.key /etc/ssl/private/vcf_https.key
chmod 644 /etc/ssl/certs/vcf_https.crt
chmod 640 /etc/ssl/private/vcf_https.key
nginx -t && systemctl reload nginx