- VMDir Expired Certificate:
- This remnant has no operational impact. If removal is desired for health-check cleanliness, follow the steps in KB 405319.
- Auto Deploy NO SKID:
- If you do not use vSphere Auto Deploy, this flag can be safely ignored. If Auto Deploy is required, replace the certificate following KB 410906.
- Clearing BACKUP_STORE Entries:
- To prevent 'Certificate Status' alarms for inactive backup certs, use the vCert utility as per KB 326268:
- Download and run the vCert Utility.
- Select Option 3 (Manage certificates).
- Select Option 12 (Clear BACKUP_STORE entries).
- LDAPS Certificate Renewal
- If an identity source certificate is expiring, update it to maintain trust:
- Refer to KB 371578 for manual steps or use vCert Option 3 > Option 11 to update LDAPS certificates without recreating the identity provider.
⚠️ IMPORTANT: Always take a file-based backup and a virtual machine snapshot of the vCenter Server before modifying certificate stores. In Enhanced Linked Mode (ELM), shut down all nodes and take snapshots simultaneously.