Renewing self-signed certificates for VxRail Manager via SDDC Manager
search cancel

Renewing self-signed certificates for VxRail Manager via SDDC Manager

book

Article ID: 451991

calendar_today

Updated On:

Products

VMware SDDC Manager / VCF Installer

Issue/Introduction

  • Provides steps to renew the VxRail Manager certificates via the SDDC Manager UI.
  • VxRail Manager certificates in Management or Workload domains are nearing expiration.
  • SDDC Manager dashboard displays certificate expiration alarms.

Environment

  • VMware Cloud Foundation (VCF) 5.x

Resolution

Note: Ensure the VxRail Manager has a snapshot or a verified file-level backup

1. Generate Certificate Signing Requests (CSRs)

  • Log in to the SDDC Manager UI.
  • Navigate to Inventory > Workload Domains.
  • Click the name of the target workload domain where the VxRail Manager resides.
  • Click the Certificates tab.
  • Select the checkbox for the VxRail Manager resource.
  • Click Generate CSRs.
  • Follow the wizard to configure details and confirm the generation.

2. Generate Signed Certificates

Note: Make sure the "openssl" certificate authority is configured: Configure OpenSSL-signed Certificates in SDDC Manager

  • From the Certificates tab, select the checkbox for the VxRail Manager resource again.
  • Click Generate Signed Certificates.
  • In the wizard, select OpenSSL from the drop-down menu.
  • Click Generate Certificates.

3. Install Certificates

  • From the Certificates tab, select the checkbox for the VxRail Manager resource.
  • Click Install Certificates.
  • Monitor the task progress in the SDDC Manager Tasks panel until completion.

Verify the VxRail Manager certificate status is marked as Valid in the SDDC Manager UI.

Additional Information

For Custom Certificate Renew/Install steps:

1. Microsoft CA Certificates

  • To renew VxRail Manager certificate with Microsoft CA, above steps are valid however for above step 2, but instead of selecting "openssl", select the Microsoft CA from the drop down menu.

Note: You must have a Microsoft CA configured as outlined in following documentation prior to above steps to complete this: Install Microsoft CA-Signed Certificates using SDDC Manager

2. Other Custom CA Certificate

For additional component certificate replacements:

NSX Manager - NSX Manager certificates replacement using SDDC Manager and VMCA in VCF 5.x

SDDC Manager - Revert SDDC Manager to using a self-signed certificate 

vCenter - Renewing self signed certificates of vCenter via SDDC manager with Open SSL integration.