Automated Machine SSL certificate replacement for vCenter Server
vCenter ships with a VMCA-signed certificate browsers do not trust. The vCenter package replaces the Machine SSL certificate with one from your CA - and keeps replacing it on every renewal.
package vcenter-target 2.0.0
replaceMachineCertificate
At a glance
- Package
vcenter-target 2.0.0- Compatibility
vCenter Server >=7.0 <9.0- Runs from
- Any Windows or Linux agent with network access to it
- Mechanism
- REST API
- Authentication
- Session login
- Capabilities
- Import certificate and key
- Deployment steps
- replaceMachineCertificate
- Rollback
- None
- Key usage
- No requirement
What it does
An agent on your network signs in to vCenter with SSO credentials and replaces the Machine SSL certificate through the certificate-management REST API, sending the certificate with its chain and the private key.
vCenter applies the new certificate itself; expect its services to restart while it does, as with a manual replacement.
How it runs
- 01
replaceMachineCertificate
Certificate, chain and key are sent to /api/vcenter/certificate-management/vcenter/tls.
What you configure
- vCenter FQDN and port
- SSO username and password, for example [email protected] (stored encrypted)
- Whether to accept the current VMCA-signed certificate for the API connection
Prerequisites
- An agent with network access to the vCenter Server appliance
- An SSO account allowed to manage certificates
- The issuing CA trusted by vCenter, so the chain is accepted
Limitations
- vCenter restarts services while applying a new Machine SSL certificate.
- ESXi host certificates are not managed by this package.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Citrix and VMware
Documentation
Frequently asked questions
VMware vCenter Server
Can I use Let's Encrypt for vCenter?
Yes, if vCenter has a publicly resolvable name validated with DNS-01. Many teams use an internal CA through the CA connector instead.
Does the package replace ESXi certificates?
No. It replaces the vCenter Server Machine SSL certificate only.
Automate VMware vCenter Server
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.