"ESXi Host Certificate Status" in the vCenter Server as shown below.Configure > System > Certificate.The vCenter Server monitors all certificates within the VMware Endpoint Certificate Store (VECS). The vCenter Server triggers a Certificate Status alarm (typically 30 days prior to expiry) if any ESXi Host Certificate is close to expiration.
Renew the ESXi host certificates using the options below:
Before attempting to renew or refresh ESXi SSL certificates, verify the following requirements:
VMCA Root Validity: Verify the VMCA Root certificate is not expired via vCenter > Administration > Certificate Management > Trusted Root.
Host Connectivity: Ensure the affected ESXi hosts are connected and in a "Green" status in the vCenter Server inventory.
Time & DNS: Verify time synchronization and functional DNS resolution between the vCenter Server and ESXi hosts.
Maintenance Mode: Remove the ESXi hosts from maintenance mode. (before ESXi 8.0 Update 3)
vCenter Machine SSL Certificate: Confirm vCenter MACHINE_SSL_CERT is valid.
Renew certificates using the VMware Certificate Authority (VMCA):
Log in to the vSphere Client and select the affected host.
Connection > ConnectNavigate to the Configure tab.
Under System, select Certificate.
Execute the renewal based on the vCenter Server version:
vCenter 8.0 Update 3 and later: Click MANAGE WITH VMCA in the upper right corner, then select Renew.
vCenter versions prior to 8.0 Update 3: Click Renew or Refresh CA Certificates directly.
Click Yes to confirm the operation.
For information regarding custom certificates, refer to the article Configuring CA signed certificates for ESXi hosts.