[VMC] Certificate Renewals - TLS Validity Periods
search cancel

[VMC] Certificate Renewals - TLS Validity Periods

book

Article ID: 439777

calendar_today

Updated On:

Products

VMware Cloud on AWS

Issue/Introduction

As part of industry-wide security changes, DigiCert is aligning with the CA/Browser Forum Ballot SC081v3, which mandates a phased reduction in public TLS certificate validity periods over the coming years:

  • 398 days → 200 days (Year 2026)
  • 200 days → 100 days (Year 2027- 2028)
  • 100 days → 47 days (Year 2029)

More details are available here: Moving to 199-day validity for public TLS certificates

Previously, certificates issued for VMC components had a validity of approximately 365 days. Effective immediately, certificates issued to VMC components will follow the reduced validity timelines outlined above.

Environment

VMware Cloud on AWS

Resolution

Impact to Your Environment

This change applies to all SDDC components and will result in a significant increase in certificate rotation frequency, not only this year but continuing in the coming years, as validity periods are further reduced.

As a result, customers should expect recurring certificate rotation activities that may require periodic maintenance windows. These activities will be planned and communicated in advance to minimize any potential impact.

Please note that this change is driven by industry standards and compliance requirements, and is not specific to VMware Cloud, and is required to ensure the ongoing security of your VMC SDDC environment.

Next Steps

Our team will coordinate with you to schedule required maintenance activities and ensure a smooth transition to the updated certificate lifecycle.

If you have any questions or would like to discuss scheduling, please feel free to reach out to support: Creating and managing Broadcom cases