Difference between "Renew" and "Refresh CA Certificates" for ESXi host certificate (managed with VMCA)
book
Article ID: 426775
calendar_today
Updated On:
Products
VMware vCenter ServerVMware vSphere ESXi
Issue/Introduction
What's the difference between "Renew" and "Refresh CA Certificates" operationfor ESXi hosts certificate on vCenter server (managed with VMCA) ?
Whats happens if issuing "Refresh CA Certificates" instead of "Renew" by mistake ?
Environment
VMware vSphere ESXi VMware vSphere vCenter
Resolution
"Rewnew" operation pushes a newly generated host certificate (signed by VMCA) to the host.
"Refresh CA certificates" operation only pushes a VMCA certificate(s) (root certificate(s)) to the host. and "Renew" operation above implicitly issues this "Refresh CA certificates".
If initiating "Refresh CA certificates" by mistake instead of "Renew", in most case nothing happens because the host already has the same VCMA's certificate(s). (of course when not renewed VMCA's root certificate) so try "Renew" operation again to update the host certificate.