Different validity periods for vCenter solution user certificates using certificate-manager
search cancel

Different validity periods for vCenter solution user certificates using certificate-manager

book

Article ID: 443399

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

VMware vCenter Server (vCenter) Solution user certificates generated using certificate-manager demonstrate different validity periods (e.g., 2 years versus matching the VMCA root expiration).

Cause

This is a known behavior within the certificate-manager utility. Providing the answer Y to the configuration file prompt (as below) strictly enforces a 2-year certificate validity cap.

Providing the answer N bypasses this cap, allowing the generated solution user certificates to inherit the maximum validity period up to the VMCA root certificate expiration.

Do you wish to generate all certificates using configuration file : Option[Y/N] ? :

 

Resolution

Broadcom engineering is aware of this behavior and it will be changed in the future builds to exhibit a common validity irrespective of the answer given during the certificate renewal using certificate-manager.

To ensure 2 years of solution certificate validity, make sure to provide "Y" to the certificate-manager utility prompt.

 

Additional Information

Using vSphere Certificate Manager to Replace SSL Certificates

Determining expired SSL certificates in vCenter Server