root@vcenter[ ~ ]# for i in $(/usr/lib/vmware-vmafd/bin/vecs-cli store list); do echo STORE $i; sudo /usr/lib/vmware-vmafd/bin/vecs-cli entry list -- store $i -- text | egrep "Alias |Not After"; doneSTORE MACHINE SSL CERTMACHINE CERTNot After : MM DD HH:MM:SS YYYY GMTNot After : MM DD HH:MM:SS YYYY GMTSTORE TRUSTED_ROOTSAlias : Alias1STORE machineAlias : machineNot After : Nov 17 17:21:23 2025 GMT ->> Certificate ExpiredSTORE vsphere-webclientAlias : vsphere-webclientNot After : Nov 17 17:21:24 2025 GMT
Alias : vpxdNot After : Nov 17 17:21:25 2025 GMTSTORE vpxd-extens ionAlias : vpxd-extensionNot After : Nov 17 17:21:25 2025 GMT
machine, vsphere-webclient, vpxd, etc.) utilized by the vCenter Server Appliance (VCSA).Utilize the vCert utility to replace the expired certificates, then restart all vCenter services
If custom-provided certificates are causing the vCenter UI login failure, replace them temporarily with the default VCSA certificates to regain access to vCenter. Afterward, re-import and apply the valid customer certificates.
Replace vCenter Machine SSL certificate Custom Certificate Authority Signed Certificate