HOWTO: Replace a VMCA certificate via the GUI in vSphere 6.5 with PSC & VCSA
Platform Services Controller vCenter VCSA VMCA VMware vSphere
Published on 25 March 2017 by Christopher Lewis. Words: 307. Reading Time: 2 mins.
Prerequisites
- A VMCA SSL Certificate (such as
root_signing_cert.cer
) - A RSA Private Key (such as
root_signing_cert.key
)
Process Overview
The high level steps are as followed:
- Log into the External Platform Services Controller.
- Replace the Root Certificate.
- Connect to the PSC Appliance.
- Renew the Machine SSL Certificate.
- Renew the Solution User Certificate.
- Connect to the VCSA Appliance.
- Renew the Machine SSL Certificate.
- Renew the Solution User Certificate.
- Reboot the Platform Services Controller.
Process Breakdown
Log into External Platform Services Controller
Navigate to https://psc-appliance.fqdn/psc
.
![](/img/2017/03/25/vmca-65-01.png)
Log in using the SSO Administrator account (e.g. administrator@vsphere.local
) and password.
![](/img/2017/03/25/vmca-65-02.png)
Renew the Root Certificate
Click Certificate Authority > Root Certificate.
![](/img/2017/03/25/vmca-65-03.png)
Click Replace Certificate.
![](/img/2017/03/25/vmca-65-04.png)
Click Browse and locate the Private Key file and click Open.
Click Browse and locate the VMCA Certificate file and click Open.
![](/img/2017/03/25/vmca-65-05.png)
Click OK.
![](/img/2017/03/25/vmca-65-06.png)
Connect to the Platform Services Controller
Click Certificate Management.
![](/img/2017/03/25/vmca-65-07.png)
Enter the SSO Administrator password and click Submit.
Renew the Machine SSL Certificate
Click the Machine Certificates tab.
![](/img/2017/03/25/vmca-65-08.png)
Select the __MACHINE_CERT
and click Renew.
![](/img/2017/03/25/vmca-65-09.png)
Click Yes.
![](/img/2017/03/25/vmca-65-10.png)
Renew the Solution User Certificates
Click the Solution User Certificates tab.
![](/img/2017/03/25/vmca-65-11.png)
Click Renew All.
![](/img/2017/03/25/vmca-65-12.png)
Click Yes.
![](/img/2017/03/25/vmca-65-13.png)
Click Logout.
![](/img/2017/03/25/vmca-65-14.png)
Connect to the vCenter Server
Enter the vcenter.fqdn
into the Server IP/FQDN text box and then enter the password for the SSO Administrator.
![](/img/2017/03/25/vmca-65-15.png)
Click Submit.
![](/img/2017/03/25/vmca-65-16.png)
Renew the Machine SSL Certificate
Click the Machine Certificates tab.
![](/img/2017/03/25/vmca-65-17.png)
Select the __MACHINE_CERT
and click Renew.
![](/img/2017/03/25/vmca-65-18.png)
Click Yes.
![](/img/2017/03/25/vmca-65-19.png)
Renew the Solution User Certificates
Click the Solution User Certificates tab.
![](/img/2017/03/25/vmca-65-20.png)
Click Renew All.
![](/img/2017/03/25/vmca-65-21.png)
Click Yes.
![](/img/2017/03/25/vmca-65-22.png)
Click Logout.
![](/img/2017/03/25/vmca-65-23.png)
Reboot the Platform Services Controller
Note: This can be completed in multiple ways but this is the way I did it.
Click Appliance Settings.
![](/img/2017/03/25/vmca-65-24.png)
Click the VMware Platform Services Appliance link.
![](/img/2017/03/25/vmca-65-25.png)
Enter username as root
and the root password, then click Logon.
![](/img/2017/03/25/vmca-65-26.png)
Click Reboot.
![](/img/2017/03/25/vmca-65-27.png)
Click Yes.
There we have it, your VCSA should now be acting as a Subordinate CA using the VMCA solution!
Published on 25 March 2017 by Christopher Lewis. Words: 307. Reading Time: 2 mins.
- HOWTO: Deploy a vSphere 6.5 vCenter Server Appliance (VCSA) ()
- HOWTO: Deploy a vSphere 6.5 External Platform Services Controller (VCSA) ()
- HOWTO: Automate the installation of the External Platform Services Controller using PowerCLI & JSON - Part 2 ()
- HOWTO: Automate the installation of the External Platform Services Controller using PowerCLI & JSON - Part 1 ()
- HOWTO: Deploy the VMware vSphere 6.0 Platform Service Controller ()
- Operating a Private Cloud - Part 3: Creating a Pricing Card in VMware Aria Automation
- Operating a Private Cloud - Part 2: Creating a Pricing Card in VMware Aria Operations
- Operating a Private Cloud - Part 1: Understanding Pricing Cards in VMware Aria
- Zero2Hero - Using Aria Automation to Deploy Multiple Machines with Multiple Disks - Part 5
- Zero2Hero - Using Aria Automation to Deploy Multiple Machines with Multiple Disks - Part 4