Starting with VMware vCenter 8.0 Update 3h, SSL certificates that the VMware Certificate Authority (VMCA) issues for vCenter and ESXi of version 8.0 Update 3 and later are automatically renewed near the expiration date. Administrative teams may require this feature to be disabled to prevent automatic service restarts during production hours or to ensure manual oversight of the certificate lifecycle. If left enabled, the VMware Certificate Authority (VMCA) will trigger a renewal and service restart automatically when the certificate enters its expiration window.
VMware vCenter Server 8.0
The parameter vpxd.certmgmt.certs.autoRenewEnabled is set to True by default. This setting directs the vCenter Server to automatically renew the Machine SSL and Solution User certificates using the internal VMCA.
Follow these steps to disable the certificate auto-renewal feature:
Edit Settings.vpxd.certmgmt.certs.autoRenewEnabledTrue to False.Note: Disabling this setting requires administrators to manually monitor certificate expiration and perform renewals via Administration > Certificate Management or the vCert utility before the certificates expire to avoid service interruption.
It is recommended to capture an offline (powered-off) snapshot of the vCenter Server Appliance before performing manual certificate renewals. Review VMware vCenter in Enhanced Linked Mode pre-changes snapshot (online or offline) best practice for additional details.