Vulnerability scan reports "Plugin ID 51192 SSL Certificate Cannot be Trusted" for vSphere ESXi server
search cancel

Vulnerability scan reports "Plugin ID 51192 SSL Certificate Cannot be Trusted" for vSphere ESXi server

book

Article ID: 393343

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

Vulnerability analysis tools generate alerts containing the following signature when assessing vSphere infrastructure components:

"The following certificate was at the top of the certificate chain sent by the remote host, but it is signed by an unknown certificate authority"

Environment

VMware vSphere ESXI 7.0.x

 VMware vSphere ESXI 8.0.x

Cause

The Certificate Authority (CA) responsible for signing the ESXi host certificates is not recognized or trusted by vulnerability scanners (e.g., Nessus, Qualys).

Resolution

Remediation of this reporting anomaly can be executed via three standard administrative approaches:

Method 1: Configuration of an Exception within the Scanner Environment

If the deployment relies on valid, default VMCA certificates, the IP addresses or Fully Qualified Domain Names (FQDNs) of the affected ESXI hosts can be whitelisted or added to an explicit exception list within the vulnerability management console.

Method 2: Implementation of Custom CA-Signed Certificates

  1. A Certificate Signing Request (CSR) must be generated for the ESXI host via the vCenter Server interface or standard CLI tools.
  2. The generated CSR must be submitted to a trusted enterprise Certificate Authority or a verified commercial Public Certificate Authority.
  3. The resulting custom certificates must be imported and assigned to the ESXI host, establishing a chain that is natively trusted by the enterprise scanning tools.

Reference KB : Step by Step Process to replace ESXI vmca certificates to Custom from vCenter UI

Method 3: Importation of the VMCA Root Bundle into the Scanner Trust Store

  1. A web browser must be directed to the vCenter Server landing page at https://<vCenter_FQDN>.
  2. The hyperlink labeled Download trusted root CA certificates must be selected from the right-hand panel.
  3. The downloaded archive file must be extracted to access the root certificates (typically with .0, .crt, or .pem extensions).
  4. These extracted root certificates must be imported directly into the custom or trusted CA certificate repository of the vulnerability scanner to establish an explicit trust alignment.

Additional Information

To speak with a customer representative or a Support Engineer, see Contact Support. Scroll to the bottom of the page and click on the respective region.