Security Scanner Reports "Invalid Maximum Validity Date Detected" on Default ESXi and vCenter Machine SSL Certificates
search cancel

Security Scanner Reports "Invalid Maximum Validity Date Detected" on Default ESXi and vCenter Machine SSL Certificates

book

Article ID: 372518

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

  • Default validity period for the ESXi host certificate is 1825 days (5 years).

  • Default validity period of MACHINE_SSL_CERT on vCenter Server using the default VMware Certificate Authority (VMCA) is 2 years (730 days).

  • Certain organizations would like to change the default validity period for the ESXi host and vCenter Machine SSL certificates.

 

Environment

VMware vSphere 7.x

VMware vSphere 8.x

Resolution

  1. Login to the vCenter UI
    • Navigate to vCenter --> Configure --> Advanced Settings --> Edit Settings
    • Filter with the setting vpxd.certmgmt.certs.daysValid
    • Change the value to by the number of days for which the certificates should be valid.
    • Click Save

  2. Now, renew the certificates on the ESXi hosts
    • Navigate to ESXi hosts individually --> Configure --> System --> Certificates
    • Click on Renew
    • Once the task is completed, refresh to see if the new Valid from and Valid to dates change accordingly.
      Note: The host should not be in maintenance mode when trying to Renew the certificate. 


  3. To renew the VMCA-signed certificates on vCenter with a desired certificate duration, follow the steps provided in https://knowledge.broadcom.com/external/article/382069