Manually Replacing the solution user certificate on VCSA/PSC 6.x
Note :
-- Take a snapshot of the VC or
PSC before proceeding.
-- PSC has two solution users : machine and
-- VC has four
solution users : machine, vpxd, vpxd-extension and vsphere-webclient.
-- VC with
embedded PSC has four
solution users : machine, vpxd, vpxd-extension and vsphere-webclient.
-- SSO admin
username and password would vary depending on the configuration.
-- Windows
Install directory may vary depending on your installation.
-- Run the
below command to get the machine ID of the node :
Appliance : /usr/lib/vmware-vmafd/bin/vmafd-cli
get-machine-id --server-name localhost
Windows :
get-machine-id --server-name localhost
0. Take a backup of the old solution user
certificates and its private keys.
Appliance :
entry getcert --store machine --alias machine --output
entry getcert --store vpxd --alias vpxd --output /root/certificate/vpxd.crt
entry getcert --store vpxd-extension --alias vpxd-extension --output
entry getcert --store vsphere-webclient --alias vsphere-webclient --output
entry getcert --store machine --alias machine --output
entry getcert --store vpxd --alias vpxd --output /root/certificate/vpxd.key
entry getcert --store vpxd-extension --alias vpxd-extension --output
entry getcert --store vsphere-webclient --alias vsphere-webclient --output
Windows :
entry getcert --store machine --alias machine --output
entry getcert --store vpxd --alias vpxd --output c:\certificate\vpxd.crt
entry getcert --store vpxd-extension --alias vpxd-extension --output
entry getcert --store vsphere-webclient --alias vsphere-webclient --output
entry getcert --store machine --alias machine --output
entry getcert --store vpxd --alias vpxd --output c:\certificate\vpxd.key
entry getcert --store vpxd-extension --alias vpxd-extension --output
entry getcert --store vsphere-webclient --alias vsphere-webclient --output
1. Create the configuration file for all the solution users :
a) machine.cfg :
[ req ]
distinguished_name =
encrypt_key = no
prompt = no
string_mask = nombstr
req_extensions = v3_req
[ v3_req ]
basicConstraints = CA:false
keyUsage = nonRepudiation,
digitalSignature, keyEncipherment
subjectAltName =
DNS:vcenter-nl-1.filmlogistics.local # FQDN of VC or PSC
[ req_distinguished_name ]
countryName = NL
stateOrProvinceName = Utrecht
localityName = Zeist
0.organizationName = VMware
organizationalUnitName = mID-74453a6d-4f01-4191-a95c-d3a905c1a516
# machine ID of the VC/PSC
commonName = machine
b) vpxd.cfg :
[ req ]
distinguished_name =
encrypt_key = no
prompt = no
string_mask = nombstr
req_extensions = v3_req
[ v3_req ]
basicConstraints = CA:false
keyUsage = nonRepudiation,
digitalSignature, keyEncipherment
subjectAltName =
DNS:vcenter-nl-1.filmlogistics.local # FQDN of VC or PSC
[ req_distinguished_name ]
countryName = NL
stateOrProvinceName = Utrecht
localityName = Zeist
0.organizationName = VMware
organizationalUnitName = mID-74453a6d-4f01-4191-a95c-d3a905c1a516
# machine ID of the VC/PSC
commonName = vpxd
c) vpxd-extension.cfg :
[ req ]
distinguished_name =
encrypt_key = no
prompt = no
string_mask = nombstr
req_extensions = v3_req
[ v3_req ]
basicConstraints = CA:false
keyUsage = nonRepudiation,
digitalSignature, keyEncipherment
subjectAltName =
DNS:vcenter-nl-1.filmlogistics.local # FQDN of VC or PSC
[ req_distinguished_name ]
countryName = NL
stateOrProvinceName = Utrecht
localityName = Zeist
0.organizationName = VMware
organizationalUnitName = mID-74453a6d-4f01-4191-a95c-d3a905c1a516
# machine ID of the VC/PSC
commonName = vpxd-extension
d) vsphere-webclient.cfg
[ req ]
distinguished_name =
encrypt_key = no
prompt = no
string_mask = nombstr
req_extensions = v3_req
[ v3_req ]
basicConstraints = CA:false
keyUsage = nonRepudiation,
digitalSignature, keyEncipherment
subjectAltName =
DNS:vcenter-nl-1.filmlogistics.local # FQDN of VC or PSC
[ req_distinguished_name ]
countryName = NL
stateOrProvinceName = Utrecht
localityName = Zeist
0.organizationName = VMware
organizationalUnitName = mID-74453a6d-4f01-4191-a95c-d3a905c1a516
# machine ID of the VC/PSC
commonName = vsphere-webclient
2. Create the certificate signing request and generate a new
certificate for all the solution certs :
Appliance :
openssl req -new -nodes -out
machine.csr -newkey rsa:2048 -keyout machine.key -config machine.cfg
openssl x509 -req -days 3650 -in
machine.csr -out machine.crt -CA /var/lib/vmware/vmca/root.cer -CAkey
/var/lib/vmware/vmca/privatekey.pem -extensions v3_req -CAcreateserial -extfile
openssl req -new -nodes -out vpxd.csr
-newkey rsa:2048 -keyout vpxd.key -config vpxd.cfg
openssl x509 -req -days 3650 -in
vpxd.csr -out vpxd.crt -CA /var/lib/vmware/vmca/root.cer -CAkey
/var/lib/vmware/vmca/privatekey.pem -extensions v3_req -CAcreateserial -extfile
openssl req -new -nodes -out
vpxd-extension.csr -newkey rsa:2048 -keyout vpxd-extension.key -config
openssl x509 -req -days 3650 -in
vpxd-extension.csr -out vpxd-extension.crt -CA /var/lib/vmware/vmca/root.cer
-CAkey /var/lib/vmware/vmca/privatekey.pem -extensions v3_req -CAcreateserial
-extfile vpxd-extension.cfg
openssl req -new -nodes -out
vsphere-webclient.csr -newkey rsa:2048 -keyout vsphere-webclient.key -config
openssl x509 -req -days 3650 -in
vsphere-webclient.csr -out vsphere-webclient.crt -CA
/var/lib/vmware/vmca/root.cer -CAkey /var/lib/vmware/vmca/privatekey.pem
-extensions v3_req -CAcreateserial -extfile vsphere-webclient.cfg
Windows :
req -new -nodes -out machine.csr -newkey rsa:2048 -keyout machine.key -config
x509 -req -days 3650 -in machine.csr -out machine.crt -CA
/var/lib/vmware/vmca/root.cer -CAkey /var/lib/vmware/vmca/privatekey.pem
-extensions v3_req -CAcreateserial -extfile machine.cfg
req -new -nodes -out vpxd.csr -newkey rsa:2048 -keyout vpxd.key -config
x509 -req -days 3650 -in vpxd.csr -out vpxd.crt -CA
/var/lib/vmware/vmca/root.cer -CAkey /var/lib/vmware/vmca/privatekey.pem
-extensions v3_req -CAcreateserial -extfile vpxd.cfg
req -new -nodes -out vpxd-extension.csr -newkey rsa:2048 -keyout
vpxd-extension.key -config vpxd-extension.cfg
x509 -req -days 3650 -in vpxd-extension.csr -out vpxd-extension.crt -CA
/var/lib/vmware/vmca/root.cer -CAkey /var/lib/vmware/vmca/privatekey.pem
-extensions v3_req -CAcreateserial -extfile vpxd-extension.cfg
req -new -nodes -out vsphere-webclient.csr -newkey rsa:2048 -keyout
vsphere-webclient.key -config vsphere-webclient.cfg
x509 -req -days 3650 -in vsphere-webclient.csr -out vsphere-webclient.crt -CA
/var/lib/vmware/vmca/root.cer -CAkey /var/lib/vmware/vmca/privatekey.pem
-extensions v3_req -CAcreateserial -extfile vsphere-webclient.cfg
3. Delete the old certificate entries from VECS store :
Appliance :
entry delete --store machine --alias machine -y
entry delete --store vpxd --alias vpxd -y
entry delete --store vpxd-extension --alias vpxd-extension -y
entry delete --store vsphere-webclient --alias vsphere-webclient -y
Windows :
entry delete --store machine --alias machine --cert machine.crt --key
entry delete --store vpxd --alias vpxd --cert vpxd.crt --key vpxd.key
entry delete --store vpxd-extension --alias vpxd-extension --cert
vpxd-extension.crt --key vpxd-extension.key
entry delete --store vsphere-webclient --alias vsphere-webclient --cert
vsphere-webclient.crt --key vsphere-webclient.key
4. Update the new certificates in the VECS store :
Appliance :
entry create --store machine --alias machine --cert machine.crt --key
entry create --store vpxd --alias vpxd --cert vpxd.crt --key vpxd.key
entry create --store vpxd-extension --alias vpxd-extension --cert
vpxd-extension.crt --key vpxd-extension.key
entry create --store vsphere-webclient --alias vsphere-webclient --cert
vsphere-webclient.crt --key vsphere-webclient.key
Windows :
entry create --store machine --alias machine --cert machine.crt --key
entry create --store vpxd --alias vpxd --cert vpxd.crt --key vpxd.key
entry create --store vpxd-extension --alias vpxd-extension --cert
vpxd-extension.crt --key vpxd-extension.key
entry create --store vsphere-webclient --alias vsphere-webclient --cert
vsphere-webclient.crt --key vsphere-webclient.key
5. List all the solution users :
service list --login administrator@vsphere.local
--password 'YA,Bkc9ID8.)o_Sxr5t6'
1. machine-74453a6d-4f01-4191-a95c-d3a905c1a516
6. Update all the solution users with the new certificate :
Appliance :
service update --name machine-74453a6d-4f01-4191-a95c-d3a905c1a516 --cert
machine.crt --login administrator@vsphere.local
--password 'YA,Bkc9ID8.)o_Sxr5t6'
service update --name vsphere-webclient-74453a6d-4f01-4191-a95c-d3a905c1a516
--cert vsphere-webclient.crt --login administrator@vsphere.local --password 'YA,Bkc9ID8.)o_Sxr5t6'
service update --name vpxd-74453a6d-4f01-4191-a95c-d3a905c1a516 --cert vpxd.crt
--login administrator@vsphere.local
--password 'YA,Bkc9ID8.)o_Sxr5t6'
service update --name vpxd-extension-74453a6d-4f01-4191-a95c-d3a905c1a516
--cert vpxd-extension.crt --login administrator@vsphere.local --password 'YA,Bkc9ID8.)o_Sxr5t6'
Windows :
service update --name machine-74453a6d-4f01-4191-a95c-d3a905c1a516 --cert
machine.crt --login administrator@vsphere.local
--password 'YA,Bkc9ID8.)o_Sxr5t6'
service update --name vsphere-webclient-74453a6d-4f01-4191-a95c-d3a905c1a516
--cert vsphere-webclient.crt --login administrator@vsphere.local
--password 'YA,Bkc9ID8.)o_Sxr5t6'
service update --name vpxd-74453a6d-4f01-4191-a95c-d3a905c1a516 --cert vpxd.crt
--login administrator@vsphere.local
--password 'YA,Bkc9ID8.)o_Sxr5t6'
service update --name vpxd-extension-74453a6d-4f01-4191-a95c-d3a905c1a516
--cert vpxd-extension.crt --login administrator@vsphere.local
--password 'YA,Bkc9ID8.)o_Sxr5t6'
7 . Update the auto-deploy, imagebuilder and eam service with
vpxd-extension certificate.
Appliance :
/usr/lib/vmware-vpx/scripts/ -e com.vmware.vim.eam -c
/certificate/vpxd-extension.crt -k /certificate/vpxd-extension.key -s
<VC_FQDN> -u <SSO_admin>
/usr/lib/vmware-vpx/scripts/ -e com.vmware.rbd
-c /certificate/vpxd-extension.crt -k /certificate/vpxd-extension.key -s
<VC_FQDN> -u <SSO_admin>
/usr/lib/vmware-vpx/scripts/ -e
com.vmware.imagebuilder -c /certificate/vpxd-extension.crt -k
/certificate/vpxd-extension.key -s <VC_FQDN> -u <SSO_admin>
Windows :
Files\VMware\vCenter Server\vpxd\scripts\
-e com.vmware.vim.eam -c C:\Certificates\vpxd-extension.crt -k
C:\Certificates\vpxd-extension.key -s <vcenter_FQDN> -u <SSO_admin>
Files\VMware\vCenter Server\vpxd\scripts\ -e
com.vmware.rbd -c C:\Certificates\vpxd-extension.crt -k
C:\Certificates\vpxd-extension.key -s <vcenter_FQDN> -u <SSO_admin>
Files\VMware\vCenter Server\vpxd\scripts\
-e com.vmware.imagebuilder -c C:\Certificates\vpxd-extension.crt -k
C:\Certificates\vpxd-extension.key -s <vcenter_FQDN> -u <SSO_admin>
8. Restart all the services.
This comment has been removed by the author.
ReplyDeleteThanks and keep sharing such valuable updates through your side.
ReplyDeletePALS Online UCR Riverside CA