ESXi host certificate status remains "expiration imminent" after renewal
search cancel

ESXi host certificate status remains "expiration imminent" after renewal

book

Article ID: 447355

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

ESX hosts display a warning stating that the certificate status is "expiration imminent." This warning persists even after you successfully renew the host certificates.

Cause

The VCSA_ROOT_CERT is approaching its expiration date. Because the VCSA_ROOT_CERT is the root certificate authority used to generate and sign all ESXi host certificates, its impending expiration cascades down the chain of trust. This causes the host certificates to trigger expiration warnings regardless of their individual creation or renewal dates.

Resolution

Replace the expiring VCSA_ROOT_CERT and subsequently renew the ESXi host certificates. Replacing the root certificate establishes a valid chain of trust with an extended validity period, allowing the newly issued host certificates to clear the expiration warnings.

  1. Replace the expiring VCSA_ROOT_CERT using the vCert tool. For detailed steps on using this utility, see vCert - Scripted vCenter expired certificate replacement
  2. Once the root certificate is replaced, renew the ESXi host certificates again using the newly generated root certificate.