vCenter Server Root Certificate Installation for Browser and Integration Trust
search cancel

vCenter Server Root Certificate Installation for Browser and Integration Trust

book

Article ID: 452926

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

When connecting to the vSphere Client or integrating third-party solutions (such as Rubrik), you may encounter certificate trust errors. Common indicators include:

  • Web browser messages: ERR_CERT_AUTHORITY_INVALID or The connection is not private.
  • Third-party integration errors: RBK20100039 - Failed to establish a secure connection to vCenter. Rubrik could not validate the SSL certificate.
  • File download failures when attempting to retrieve files directly from ESXi hosts.

Environment

  • VMware vCenter Server 6.x, 7.x, and 8.x
  • VMware vSphere ESXi
  • Windows Desktop Operating Systems

Cause

The vCenter Server and ESXi host root CA certificates are missing from the workstation's or application server's Trusted Root Certification Authorities store. Without these certificates, the operating system cannot validate the identity of the vCenter Server.

Resolution

To resolve this issue, download the root CA certificates from the vCenter Server and install them into the local trust store.

Step 1: Download the Root Certificates

  1. Open a web browser and navigate to the vCenter Server FQDN (e.g., https://vcenter.####.####/).
  2. Click the Download trusted root CA certificates link located in the bottom-right gray box.
  3. Save the download.zip file to your local machine.
  4. Extract the contents of the ZIP file. You will find a .certs folder containing files with numeric extensions (e.g., .0.1). These are the root certificates.

Step 2: Install Certificates (Windows)

  1. Click Start, type mmc, and press Enter.
  2. Go to File > Add/Remove Snap-in.
  3. Select Certificates, click Add, select Computer Account, and click Finish.
  4. Click OK to return to the console.
  5. Expand Certificates (Local Computer) > Trusted Root Certification Authorities.
  6. Right-click Certificates, select All Tasks > Import.
  7. Follow the wizard to import the certificate files extracted in Step 1. Ensure you select Place all certificates in the following store: Trusted Root Certification Authorities.
  8. Restart your web browser or integration service to apply the changes.

Additional Information

For more information on managing certificates, see vSphere Certificate Requirements.

To speak with a customer representative or a Support Engineer, see Contact Support. Scroll to the bottom of the page and click on your respective region.