"ESXi Host Certificate Status" alert in vCenter Server - VMware vSphere ESXi
search cancel

"ESXi Host Certificate Status" alert in vCenter Server - VMware vSphere ESXi

book

Article ID: 374032

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

  • An ESXi host is marked with an alarm stating "ESXi Host Certificate Status" in the vCenter Server as shown below.

  • The alert triggers when the ESXi Host Certificate is nearing or past the expiration date within the VMware Endpoint Certificate Store (VECS).

  • View the certificate validity in the vSphere Client by selecting the ESXi host object and navigating to Configure > System > Certificate.

Environment

  • VMware vSphere ESXi 7.x

  • VMware vSphere ESXi 8.x

  • VMware vSphere ESX 9.x

Cause

The vCenter Server monitors all certificates within the VMware Endpoint Certificate Store (VECS). The vCenter Server triggers a Certificate Status alarm (typically 30 days prior to expiry) if any ESXi Host Certificate is close to expiration.

Resolution

Renew the ESXi host certificates using the options below:

Prerequisites

Before attempting to renew or refresh ESXi SSL certificates, verify the following requirements:

  1. VMCA Root Validity: Verify the VMCA Root certificate is not expired via vCenter > Administration > Certificate Management > Trusted Root.

  2. Host Connectivity: Ensure the affected ESXi hosts are connected and in a "Green" status in the vCenter Server inventory.

  3. Time & DNS: Verify time synchronization and functional DNS resolution between the vCenter Server and ESXi hosts.

  4. Maintenance Mode: Remove the ESXi hosts from maintenance mode. (before ESXi 8.0 Update 3)

  5. vCenter Machine SSL Certificate: Confirm vCenter MACHINE_SSL_CERT is valid.

Renew certificates using the VMware Certificate Authority (VMCA):

  1. Log in to the vSphere Client and select the affected host.

  2. If the host shows disconnect, right-click the host and select Connection > Connect
  3. Navigate to the Configure tab.

  4. Under System, select Certificate.

  5. Execute the renewal based on the vCenter Server version:

    • vCenter 8.0 Update 3 and later: Click MANAGE WITH VMCA in the upper right corner, then select Renew.

    • vCenter versions prior to 8.0 Update 3: Click Renew or Refresh CA Certificates directly.

  6. Click Yes to confirm the operation.

Additional Information

For information regarding custom certificates, refer to the article Configuring CA signed certificates for ESXi hosts.