An ESXi host is marked with an alarm stating "ESXi Host Certificate Status" in the vSphere Client. This occurs when the host's SSL certificate is nearing or past its expiration date.
vCenter 7.x
vCenter 8.x
vCenter Server monitors all certificates within the VMware Endpoint Certificate Store (VECS). It triggers a Certificate Status alarm (typically 30 days prior to expiry) if any host certificate is close to expiration.
Follow these steps to renew certificates using the VMware Certificate Authority (VMCA):
If the host is disconnected or the UI is unresponsive, use an SSH session:
/sbin/generate-certificates/etc/init.d/hostd restart/etc/init.d/vpxa restartBefore attempting to renew or refresh ESXi SSL certificates, you must verify the following:
MACHINE_SSL_CERT must be valid.Refer to KB Configuring CA signed certificates for ESXi hosts.