NOTE: Take a snapshot of the vCenter server appliance, and ensure you have a valid backup before proceeding.
- Verify expiration by choosing: 2. View certificate info, then 9. VMCA certificate. If the expiration date matches the expiration date of any subordinate certificates, proceed with the next steps.
- To replace the VMCA certificate and all subordinate certs, choose 3. Manage certificates from the main menu of vCert and then 9. VMCA certificate.
- If you are using a VMCA root certificate signed by an external CA and wish to replace it with an updated certificate, choose Option 1 and provide the certificate from your external CA.
- If you are using default, self-signed certificates select 2. Replace VMCA certificate with a self-signed certificate and regenerate all certificates.
- Authenticate with the SSO administrator user. If you are using option 2, accept all default values for the certificate when prompted.
- When prompted to replace the STS Signing Cerificate, choose Yes.
- Restart services when prompted.
- Log into the vCenter web client to further confirm the issue is resolved.
NOTE: After replacing the VMCA root certificate, it will be necessary to replace all ESXi certificates. This can be done without an outage of the hosts or VMs on the hosts.
- Log in to the vSphere Client and select the affected host.
- Navigate to the Configure tab.
- Under System, select Certificate.
- Execute the renewal based on your vCenter version:
- vCenter 8.0 Update 3 and later: Click MANAGE WITH VMCA in the upper right corner, then select Renew.
- vCenter versions prior to 8.0 Update 3: Click Renew or Refresh CA Certificates directly.