VxRail: Updating Dell VxRail with Custom Certificates (Customer Correctable)

Summary: Step-by-step guidance to replace with customer certificates for Dell VxRail environments. vSphere provides security by using certificates to encrypt communications, authenticate services, and sign tokens. ...

Acest articol se aplică pentru Acest articol nu se aplică pentru Acest articol nu este legat de un produs specific. Acest articol nu acoperă toate versiunile de produs existente.

Instructions

vSphere uses certificates to:

  • Encrypt communications between two nodes, such as vCenter Server and an ESXi host.
  • Authenticate vSphere services.
  • Perform internal actions such as signing tokens.

vSphere's internal certificate authority, VMware Certificate Authority (VMCA), provides all the certificates necessary for vCenter Server and ESXi. VMCA is installed on every Platform Services Controller, immediately securing the solution without any other modification. Keeping this default configuration provides the lowest operational overhead for certificate management. vSphere provides a mechanism to renew these certificates in the event they expire.

vSphere also provides a mechanism to replace certain certificates with your own certificates. However, it is advised to replace only the SSL certificate that provides encryption between nodes, to keep your certificate management overhead low.

Custom Certificate Integration

The vSphere environment is flexible to give the customers the opportunity to work with custom SSL certificates, as their company policies sometimes mandate that. The following steps walk you through changing certificates for various components in a VxRail environment.

  1. Replacing VxRail Manager's self-signed certificate
    • The certificate can be replaced using the VxRail manager plugin: In vSphere select the cluster level >Configure > Security > Certificate. For guidance on creating the Certificate Signing Request and modifying the received cert files, see KB article VxRail: How to apply for a new certificate for VxRail Manager.
  2. Replacing vCenter Server certificates using a Custom Certificate Authority (CA) Signed Certificate
  3. Manually reestablishing trust between VxRail Manager and vCenter Server after custom certificate integration
  4. Replacing ESXi host SSL certificates
  5. Replacing vRealize Log Insight certificates
Note: Generating Certificate Signing Requests (CSRs) using third-party tools or signing them using the internal company's CA is not supported by Dell support.

If you face any issues during certificate replacement, reach out to Dell support for assistance.

Produse afectate

VxRail, VxRail Appliance Family
Proprietăți articol
Article Number: 000019755
Article Type: How To
Ultima modificare: 12 Jun 2025
Version:  15
Găsiți răspunsuri la întrebările dvs. de la alți utilizatori Dell
Servicii de asistență
Verificați dacă dispozitivul dvs. este acoperit de serviciile de asistență.