Disclaimer The views expressed anywhere on this site are strictly mine and not the opinions and views of VMware or anyone else. Updating the SSL Certificate for your host Should you change your host's hostname or domain after an install, the SSL certificate for the host will still be issued to localhost.localdomain. Please type your message and try again. 3 Replies Latest reply: Feb 7, 2014 5:39 AM by rh5592 vSphere Web Client SSL Certificate error (vCenter Appliance) CaptainL Feb 7, 2014 4:41 Open up a console through the remote management card or KVM to the target host and log in as root to the Direct Console User Interface (DCUI - F2 on the

Login to DCUI Select Troubleshooting Options -> Select Restart Management Agents. These instructions are for 5.0 only. On the system where you will generate the certificate signing request (rui.csr) you will need to ensure you have Microsoft Visual C++ 2008 Redistributable Package (x86) before installing OpenSSL. I also had to wait 24 hours to be able to update the certificates for these hosts.

Reply @vcdxnz001 January 10, 2013 at 10:56 pm | Permalink Hi Harry, the MS patch I referred to would also impact your clients (i.e. Then press Enter. 6) Select Y (Yes) when prompted to save changes and restart the management network. We are using an internal CA. Related PostsVMware vRealize Management Packs for Nutanix→Licensing Databases In a Virtualized Environment - Eradicate the Terrorists Of Your Datacenter→VMTURBO VMWORLD® 2016 SWEEPSTAKES→Oracle Licensing and Support on VMware: Awaken the FUD in

I will be posting instruction guides, how-to, troubleshooting tips and tricks on Linux, database, hardware, security and web. - x.509 IETF RFC 3280 - X.509 Each component in your vSphere Infrastructure uses these X.509 SSL certificates for secure encrypted communications. Copy the files to a backup location, such as a VMFS volume. Thanks again Reply @vcdxnz001 June 6, 2013 at 11:20 am | Permalink Hi Harry, Correct re step 16 for ESXi.

Enter "testpassword" whenever it prompts for a password. Error: Start Time Error (70034). --> ", --> msg = "" --> } --> Args: --> --> Arg host: --> (ManagedObjectReference) [ --> 'vim.HostSystem:2306b49d-4fc5-4bdf-96e0-80a1da9b8633:host-17' --> ] Step 1. During my VCAP4-DCA study I went through changing SSL certs and it's a lengthy process and like you said the documentation is all over the place! So, I would say that steps 19 - 23 aren't needed, I still had to follow step 18.

This means you can't just take one cert generated for vCenter for example and apply it to all of your hosts. Thanks Rommel!In my case i only needed to disable the Certificate regeneration option. Press F2 to log in to the Direct Console User Interface (DCUI). You might see an error message such as this: And also see something like this, an HA election that never ends: You might also see this in your fdm.log in /var/log

You will also notice as you read through all of these documents and kb articles that there is a lack  of consistency. blank/no password) when it asks you for a password at the end. RDP into the vCenter Server, and go to: %programdata%\VMware\VMware VirtualCenter\SSL 10. For the purposes of this process you will use the Microsoft CA Web Pages to submit the certificate request and download the resulting base-64 encoded certificate.

It came up when I was first searching on this error via Google and […] Jeremy Hagan March 7, 2013 at 11:57 pm | Permalink Is this procedure identical for ESXi This article will focus on successfully changing the default VMware SSL certificates on vCenter 5 […] Nick Evans February 7, 2012 at 8:59 am | Permalink Great post Michael. Verify SSL Certificate Checking « - An online community discussing the advantages of leveraging Cloud Computing February 17, 2013 at 6:40 am | Permalink […] if you want more After the configuration and a couple of reboots, i navigate to the web client and i get this error when i try to log-in :"Based on the current configuration, the SSL

If you would like to read the other articles in this series, they are listed here for your convenience. The article states that ESXi hosts added to the vCenter before replacing the CA certificate will not be affected. Remove the \tmp\ directory from the linux server. Like Show 0 Likes (0) Actions 3.

Reply @vcdxnz001 May 26, 2012 at 7:50 pm | Permalink Correct, the hosts should have been ok after exiting maintenance mode, as the expected SSL thumbprint should have been updated in Verify SSL Certificate Checking | Wahl Network February 1, 2013 at 3:02 am | Permalink […] if you want more certificate goodness, check out fellow VCDX Michael Webster's post on "The Edit the openssl.cfg file and ensure it looks similar to the one included at the bottom of this article but with your organization specific information, save the configuration. Essentially the host reconnect script does the same thing.

But it's interesting that my hosts stayed in "election" status until I disconnected and reconnected. The step is this: After changing the certificates, restarting the management agents on the host, and existing maintenance mode, wait for HA to configure and fail. Misconfiguration in the host setup vSphere 5 Security Guide Replacing vCenter Server 4.1 Certificates Generating Domain Root CA signed certificates for vCenter Server The Trouble with CA SSL Certificates and vCenter You would want to do this if you changed the ESXi host name and you need to generate new certificates that match the new hostname, or if the certificate is about

Part 5: HOW TO: Enable SSH Remote Access on a VMware vSphere Hypervisor 5.1 (ESXi 5.1) Part 6: HOW TO: Create your first Linux Virtual Machine on a VMware vSphere Hypervisor There is nothing in the upgrade process itself that would require you to upgrade your SSL certificates. Using the VI client 1) Go to Configuration tab and select DNS and Routing 2) Click on Properties to open the DNS and Routing Configuration screen 3) Enter the name and Reply Erik Verbruggen -September 7, 2015 - 8:43 am 247 VMware has published a KB article which confirms the 24 hour wait period.

Re: vSphere Web Client SSL Certificate error (vCenter Appliance) CaptainL Feb 7, 2014 5:36 AM (in response to rh5592) That did the trick! All rights reserved. I need now to go through an approved CA and I have been trying to get the specific x509 certificate attributes (keyUsage) that need to be included in the CSR but The change will take place immediately.

Home About HP & VMware Links ESXi-Customizer-PS ESXi Community Packaging Tools ESXi-Customizer V-Front Online Depot ESXi Patch Tracker ESXi 5.x/6.x Patch Matrix Impressum (German) How to avoid browser warnings when using It's covered in the VMware KB's and I haven't specifically documented it here. Enter your domain and credentials. Scroll down the screen till you reach Troubleshooting Options, then press enter.

These files then can be used to generate .cer file (certificate) which can be installed on ESXi.