Remediating SSL Certificate Vulnerabilities on ESXi 8.0.3 with Enterprise CA
search cancel

Remediating SSL Certificate Vulnerabilities on ESXi 8.0.3 with Enterprise CA

book

Article ID: 451950

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

This article provides the procedure to remediate SSL certificate-related vulnerabilities (Plugin IDs 38169, 38173, and 38685) on ESXi 8.0.3 hosts by replacing self-signed certificates with certificates issued by an internal enterprise Certificate Authority (CA).

Environment

ESXi

vCenter Server 

Resolution

  1. Preparation: Set the vCenter vpxd.certmgmt.mode advanced setting to custom to ensure the VMware Certificate Authority (VMCA) does not revert custom certificates.
  2. Certificate Issuance: Generate a Certificate Signing Request (CSR) for the ESXi host using the vSphere Client.
  3. CA Signing: Submit the CSR to your internal Enterprise CA (e.g., Venafi, Microsoft CA). Ensure the certificate validity period is 398 days or fewer.
  4. Replacement: Apply the signed certificate using the vSphere Client.
  5. Validation: Verify the certificate installation in the vSphere Client and rescan with your vulnerability scanner.