Knowledge Base
The VMware Knowledge Base provides support solutions, error messages and troubleshooting guides

|
Implementing CA signed SSL certificates with vSphere 5.1 (2034833)
Purpose
This article provides information on manually configuring Certificate Authority (CA) signed SSL certificates in a vSphere 5.1 environment. VMware has released a tool to automate much of the described process below. Please see Deploying and using the SSL Certificate Automation tool (2041600) before following the steps in the article.
In the case that you are unable to use the tool this article helps you eliminate common causes for problems during certificate implementation, including configuration steps and details, and helps avoid common misconfigurations in the implementation of custom certificates in your environment.
Note: This article is specifically for vSphere 5.1. If you are using vSphere 5.0, see Implementing CA signed SSL Certificates with vSphere 5.0 (2015383).
Resolution
Configuring CA signed certificates is a challenge with vSphere as with any complex enterprise environment. Securing an environment is a requirement in many large organizations. You need either public certificates (such as Verisign or Globaltrust), Microsoft CA certificates, or OpenSSL CA certificates to ensure a secure communication.
This article provides steps to allow configuration of these certificates on vSphere components in an environment. The article also assumes that all components are installed and running already with self-signed certificates.
Please validate each step below. Each step provides instructions or a link to a document that provides information on configuring the certificates in your environment.
-
Generate certificate requests and certificates for each of the vCenter Server components. For more information, see Creating certificate requests and certificates for the vCenter Server 5.1 components (2037432).
-
Replace the vCenter SSO certificates. For more information, see Configuring CA signed SSL certificates for vCenter SSO in vCenter Server 5.1 (2035011).
-
Replace the Inventory Service certificates. For more information on this, see Configuring CA signed SSL certificates for the Inventory service in vCenter Server 5.1 (2035009).
-
Replace the vCenter Server 5.1 certificates. For more information, see Configuring CA Signed Certificates for vCenter Server 5.1 (2035005).
-
Replace the vSphere Web Client certificates. For more information, see Configuring CA signed SSL certificates for the vSphere Web Client and Log Browser in vCenter Server 5.1 (2035010).
-
Replace the vSphere Update Manager Update Manager Certificates. For more information, see Configuring CA signed SSL certificates for VMware Update Manager in vSphere 5.1 (2037581).
-
Replace ESXi 5.x host certificates. For more information, see Configuring CA signed SSL certificates with ESXi 5.x hosts (2015499).
If your issue persists even after trying these steps:
- Collect the custom certificate configuration information, including the OpenSSL configuration file (normally openssl.cfg), rui.key, rui.crt, and rui.csr.
- Gather the VMware Support Script Data. For more information, see Collecting diagnostic information for VMware products (1008524).
- File a support request with VMware Support, include the gathered information, and note this Knowledge Base article ID (2034833) in the problem description. For more information, see Filing a Support Request in My VMware (2006985).
See Also
- Filing a Support Request in My VMware
- Configuring CA signed certificates for ESXi 5.x hosts
- Configuring CA signed certificates for vCenter Server 5.1
- Configuring CA signed SSL certificates for the Inventory service in vCenter Server 5.1
- Configuring CA signed SSL certificates for the vSphere Web Client and Log Browser in vCenter Server 5.1
- Configuring CA signed SSL certificates for vCenter Server SSO in vCenter Server 5.1
- Creating certificate requests and certificates for vCenter Server 5.1 components
- Configuring CA signed SSL certificates for vSphere Update Manager in vCenter Server 5.1
- Deploying and using the SSL Certificate Automation Tool
Request a Product Feature
To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.
Actions
KB:
- Updated:
- Categories:
- Languages:
- Product Family:
- Product(s):
- Product Version(s):

