Replace the expiring certificates in the TRUSTED_ROOTS store without replacing the Machine SSL Certificate
book
Article ID: 417420
calendar_today
Updated On:
Products
VMware vCenter Server
Issue/Introduction
Root, Intermediate or Signing certificate is expiring or expired.
Renewed the expiring or expired certificate in the Internal CA.
vCenter Machine SSL Certificate is still valid for some more time.
Replace the expiring or expired Root, Intermediate or Issuer certificate without replacing the current Machine SSL Certificate.
Environment
vCenter 7.x
vCenter 8.x
vCenter 9.x
Resolution
It is possible to replace the expired or expiring CA Certificate in the TRUSTED_ROOTS store without replacing the current machine SSL. To perform the replacement, follow the steps below.
SSH in to vCenter and restart all the service to ensure the vCenter functionality is intact. service-control --stop --all && service-control --start --all