https://knowledge.broadcom.com/external/article?legacyId=83558
Article ID: 318197
Updated On: 02-03-2025
Products
Issue/Introduction
This article provides information on how to replace certificates using H5C UI in vCenter server 7.0 Update 3 and later
Symptoms:
There will be an alert in the vSphere UI:
STS Signing Certificates are about to expire
Environment
Resolution
To Update the STS signing certificate using H5C UI:
Steps to Update the Certificate:
Note: Before making any changes, please create offline or cold snapshots of all the vCenter servers in the environment.
In an Enhanced Linked Mode (ELM) setup, this should be performed on a single vCenter, and a restart of all systems in the SSO domain is required afterward.
Connect to the vSphere HTML5 client through https://vcenter_server_ip_address_or_fqdn/ui
From Home Menu, Select Administration.
Under Certificates, Click on Certificate Management.
From the STS signing certificate card Actions drop down, this will be seen:
Click on Refresh button in the Refresh with vCenter Certificate Dialog Window:
In some environments, the 'Refresh with vCenter Certificate' dialog's Refresh button may be replaced with a 'Force Refresh' button. Additionally, Clicking on the 'Refresh' button may bring up a new 'Refresh with vCenter Certificate' dialog with a 'Force Refresh' button. clicking on Force Refresh requires rebooting all systems and may render systems not able to be used. If restarting all systems is not an option or if there is a concern on the consequences of 'Force Refresh', press cancel.
This will be taken back to the same dialog with an error message displayed. Press cancel and follow KB: "Signing certificate is not valid" error in vCenter Server Appliance
Using the 'Refresh' action will replace any 3rd party/custom certificates with vCenter-issued certificates. If the 3rd party/custom certificates are required for compliance reasons, this will take the vSphere out of compliance.
Select a PEM file which contains a valid certificate chain with the leaf cert marked for digital signature key usage and the corresponding unencrypted private key.
Refresh with vCenter certificate (Recommended)
Import and Replace Certificate (This is to provide certificates such as custom or third-party certificates):
Upon the successful Import and Replace/Refresh action, the UI may indicate that rebooting of all systems is required. If indicated, all systems in the SSO domain must be restarted manually (VC/PSCs)
Additional Information
"Signing certificate is not valid" error in vCenter Server Appliance
- For more information on STS certificates, See Security Token Service STS.
Impact/Risks:
If the STS signing certificates expire without replacing them, vSphere will no longer be functional.
推荐本站淘宝优惠价购买喜欢的宝贝:
本文链接:https://sg.hqyman.cn/post/9379.html 非本站原创文章欢迎转载,原创文章需保留本站地址!
休息一下~~