aethercert
Citrix and VMware

Automated Machine SSL certificate replacement for vCenter Server

vCenter ships with a VMCA-signed certificate browsers do not trust. The vCenter package replaces the Machine SSL certificate with one from your CA - and keeps replacing it on every renewal.

The deployment steps defined in this package's manifest.

At a glance

Package
vcenter-target 2.0.0
Compatibility
vCenter Server >=7.0 <9.0
Runs from
Any Windows or Linux agent with network access to it
Mechanism
REST API
Authentication
Session login
Capabilities
Import certificate and key
Deployment steps
replaceMachineCertificate
Rollback
None
Key usage
No requirement

What it does

An agent on your network signs in to vCenter with SSO credentials and replaces the Machine SSL certificate through the certificate-management REST API, sending the certificate with its chain and the private key.

vCenter applies the new certificate itself; expect its services to restart while it does, as with a manual replacement.

How it runs

  1. 01

    replaceMachineCertificate

    Certificate, chain and key are sent to /api/vcenter/certificate-management/vcenter/tls.

What you configure

  • vCenter FQDN and port
  • SSO username and password, for example [email protected] (stored encrypted)
  • Whether to accept the current VMCA-signed certificate for the API connection

Prerequisites

  • An agent with network access to the vCenter Server appliance
  • An SSO account allowed to manage certificates
  • The issuing CA trusted by vCenter, so the chain is accepted

Limitations

  • vCenter restarts services while applying a new Machine SSL certificate.
  • ESXi host certificates are not managed by this package.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Frequently asked questions

VMware vCenter Server

Can I use Let's Encrypt for vCenter?

Yes, if vCenter has a publicly resolvable name validated with DNS-01. Many teams use an internal CA through the CA connector instead.

Does the package replace ESXi certificates?

No. It replaces the vCenter Server Machine SSL certificate only.

Automate VMware vCenter Server

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.