replacing root or intermediate Certificate from vsphere UI do not update embedded CA certificates and old Certificate reappear.
search cancel

replacing root or intermediate Certificate from vsphere UI do not update embedded CA certificates and old Certificate reappear.

book

Article ID: 452479

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

- Certificate alerts in vCenter indicating machine_ssl is going to expire as well as expired certificate in TRUSTED_ROOTS store.

- vSphere client show that the TRUSTED_ROOTS store contains expired certificate which is part of the chain that did sign the machine_ssl certificate.

- the machine_ssl certificate is not expired yet however.

listing the machine_ssl certificate from VECS show the chain with the expired certificate.

 

Environment

vCenter 8.u3

Cause

replacing and removing the root certificate from vsphere client does not update the embedded CA certificate and the old certificate reappear.

Resolution

use vCert to remove the old certificate and to pusblish the new one. this will also update the embedded CA cert in vecs :

vCert output: