In our last post Replacing vSphere 6 SSL Certificates we learned how to replace Machine certificates and VMCA root certificates. In this post we will learn how to replace Esxi default ssl certificates with certificates signed by CA server.
If you have missed earlier posts of this series, then you can read them from below links
1: Setup CA Server for vSphere Lab
2: Set Up Automatic Certificate Enrollment
3: Request Internal Certificate from CA Server
4: Everything You Should Know About Certificate Management in vSphere 6
5: Replacing vSphere 6 SSL Certificates
ESXi host uses default certificates that are created during installation. These certificates are not verifiable and are not signed by a trusted certificate authority. If using default certificates do not fall under security policy of your organization, then you need the self-signed certificates from your CA server.
Note: ESXi hosts that are upgraded from vSphere 5.x to vSphere 6.0 will continue using their Certificate Authority signed certificates if they were replaced in the previous versions.… Read More