Regarding the need to generate a new CSR when renewing a vCenter server certificate.
search cancel

Regarding the need to generate a new CSR when renewing a vCenter server certificate.

book

Article ID: 417313

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

This article explains whether it is possible to re-use a previously generated CSR to renew a new vCenter certificate when an external CA is renewed.

Environment

vCenter Server

Resolution

While it is technically possible to reuse an existing CSR to generate a new server certificate, this practice is not recommended from a security standpoint.
Unless there is a specific requirement to reuse the old CSR, you should generate a new CSR that reflects the current environment and use it to issue the updated server certificate.

Additional Information

Japanese Version: vCenter サーバ証明書を更新する際に新規にCSRを生成する必要性について