Post replacing the vCenter Machine SSL custom certificate with a new one, still seeing alerts related to certificates about to expire in vSphere UI
book
Article ID: 414439
calendar_today
Updated On:
Products
VMware vCenter Server
Issue/Introduction
When replacing the machine SSL certificate with a custom certificate, it successfully replaces one. However post this, the alert "certificates about to expire" still shows up on the vSphere UI.
No expired certificates are present in the Backup Store.
The TRUSTED_ROOTS store has an expired issuer certificate.
Environment
VMware vCenter Server 7.x VMware vCenter Server 8.x
Cause
There is still an expired issuer certificate present in the TRUSTED_ROOTS store. Post running the vCert utility, the same gets added to the MACHINE_SSL_CERT store too.
Resolution
Remove the expired issuer certificate in the TRUSTED_ROOTS store by following either the Manual Method or Scripted Method.
Once the old certificate is removed, add the new signing certificate to the TRUSTED_ROOTS store manually.