Procedure to renew expired Machine Certificate:
· SSH to the vCenter Server Appliance (VCSA).
· Login with vCenter root credential
· Type shell then enter
· Run : /usr/lib/vmware-vmca/bin/certificate-manager
· Select Option 3: Replace Machine SSL certificate with VMCA Certificate
Follow the Prompts:
· vCenter SSO username (e.g., administrator@vsphere.local)
· SSO password
After entering required certificate details and confirming, the script will:
- Generate a new certificate
- Replace the expired machine SSL certificate
- Restart necessary services