Replacing expiring or expired vCenter certificates does not change the expiration date of the certificates
search cancel

Replacing expiring or expired vCenter certificates does not change the expiration date of the certificates

book

Article ID: 446297

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

When replacing vCenter certificates that are expiring or have expired, the expiration date does not change to a date forward in time.

Environment

VMware vCenter Server 9.0
VMware vCenter Server 8.0
VMware vCenter Server 7.0

Cause

The VMCA root certificate is also expiring. Certificates issued by the VMCA root certificate will have a maximum expiration date that matches the VMCA root certificate.

Resolution

NOTE: Take a snapshot of the vCenter server appliance, and ensure you have a valid backup before proceeding.
 
Follow the vCert - Scripted vCenter expired certificate replacement KB to install the script.
 
  1. Verify expiration by choosing: 2. View certificate info, then 9. VMCA certificate. If the expiration date matches the expiration date of any subordinate certificates, proceed with the next steps.
  2. To replace the VMCA certificate and all subordinate certs, choose 3. Manage certificates from the main menu of vCert and then 9. VMCA certificate
  3. If you are using a VMCA root certificate signed by an external CA and wish to replace it with an updated certificate, choose Option 1 and provide the certificate from your external CA.
  4. If you are using default, self-signed certificates select 2. Replace VMCA certificate with a self-signed certificate and regenerate all certificates.
  5. Authenticate with the SSO administrator user. If you are using option 2, accept all default values for the certificate when prompted.
  6. When prompted to replace the STS Signing Cerificate, choose Yes. 
  7. Restart services when prompted.
  8. Log into the vCenter web client to further confirm the issue is resolved.

NOTE: After replacing the VMCA root certificate, it will be necessary to replace all ESXi certificates. This can be done without an outage of the hosts or VMs on the hosts. 
 
  1. Log in to the vSphere Client and select the affected host.
  2. Navigate to the Configure tab.
  3. Under System, select Certificate.
  4. Execute the renewal based on your vCenter version:
    • vCenter 8.0 Update 3 and later: Click MANAGE WITH VMCA in the upper right corner, then select Renew.
    • vCenter versions prior to 8.0 Update 3: Click Renew or Refresh CA Certificates directly.

Additional Information

vCert - Scripted vCenter expired certificate replacement


Replacing VMCA root certificate with vCert