Custom certificates cannot be renewed using the "Renew" function in vSphere Client.
As with the initial installation, you must generate a CSR (Certificate Signing Request) and import the newly issued certificate.
- Generate the CSR
- Log in with the vSphere Client to the vCenter Server.
- Specify the user name and password for [email protected] or another member of the vCenter Single Sign-On Administrators group.
If you specified a different domain during installation, log in as administrator@mydomain.
- Navigate to the Certificate Management UI.
- From the Home menu, select Administration.
- Under Certificates, click Certificate Management.
- Enter the credentials of your vCenter Server.
- Generate the CSR.
- Under the Machine SSL tab, select the desired certificate and click Generate Certificate Signing Request (CSR).
- Enter your certificate information and click Next.
- Copy or download the CSR.
- Click Finish.
- Provide the CSR to your Certificate Authority.
Note:
For certificate requirements, see Generating a Certificate Signing Request for a Machine SSL Certificate using the vSphere Client (Custom Certificates) .
- Importing a Custom Certificate
- Log in with the vSphere Client to the vCenter Server.
- Specify the user name and password for [email protected] or another member of the vCenter Single Sign-On Administrators group.
If you specified a different domain during installation, log in as administrator@mydomain.
- Navigate to the Certificate Management UI.
- From the Home menu, select Administration.
- Under Certificates, click Certificate Management.
- If the system prompts you, enter the credentials of your vCenter Server.
- Under the Machine SSL tab, select the certificate then click Import and Replace Certificate.
- Click the "Replace with external CA certificate (requires private key)" option and click Next.
- Enter the CSR information, or upload the appropriate certificates.
- Click the checkbox to acknowledge that you have backed up vCenter Server and its databases.
- Review the information and click Finish.
The system replaces the certificate and displays a success message.
- When the certificate has been changed message appears, click Refresh to refresh your browser.