Difference between "Renew" and "Refresh CA Certificates" for ESXi host certificate (managed with VMCA)
search cancel

Difference between "Renew" and "Refresh CA Certificates" for ESXi host certificate (managed with VMCA)

book

Article ID: 426775

calendar_today

Updated On:

Products

VMware vCenter Server VMware vSphere ESXi

Issue/Introduction

  • What's the difference between "Renew" and "Refresh CA Certificates"  operation for ESXi hosts certificate on vCenter server (managed with VMCA) ?
  • Whats happens if issuing "Refresh CA Certificates" instead of "Renew" by mistake ?

Environment

VMware vSphere ESXi
VMware vSphere vCenter

Resolution

  • "Rewnew" operation pushes a newly generated host certificate (signed by VMCA) to the host.
  • "Refresh CA certificates" operation only pushes a VMCA certificate(s) (root certificate(s)) to the host. and "Renew" operation above implicitly issues  this "Refresh CA certificates".

  • If initiating "Refresh CA certificates" by mistake instead of "Renew", in most case nothing happens because the host already has the same VCMA's certificate(s). (of course when not renewed VMCA's root certificate) so try "Renew" operation again to update the host certificate.