āļ§āļīāļāļĩāļāļēāļĢāļāļīāļāļāļąāđāļ SSL āđāļŦāđāļāļąāļ VMCenter , vCenter , VMWare Center āđāļāļ·āđāļāđāļāđāļāļēāļ āđāļĨāļ°āđāļāļ·āđāļāļĄāļāđāļ VM Server āļāļĒāđāļēāļāļāļĨāļāļāļ āļąāļĒāļāđāļēāļ HTTPS āļāđāļ§āļĒāđāļāļĢāļąāļāļĢāļāļāļāļ§āļēāļĄāļāļĨāļāļāļ āļąāļĒāđāļāđÂ
1. āļĨāđāļāļāļāļīāļāļāļĩāđ vCenter āļāđāļ§āļĒ user administrator āļŦāļĢāļ·āļ āļĢāļ°āļāļąāļ administrator
- āđāļāļĒāļąāļāđāļĄāļāļđ Menu > Administration > Certificates > Certificate Management.
 - āđāļĨāļ·āļāļ Machine SSL Certificate > Actions, āđāļĨāļ·āļāļ Import and Replace Certificate
2. āđāļĨāļ·āļāļ Replace with external CA Certificate (require private key)
Â
Â
2. āļāļģāļāļēāļĢāļāļąāļāđāļŦāļĨāļ Domain.crt , Private.key , CARoot.crt
āļāļģāļāļēāļĢāļāļąāļāđāļŦāļĨāļāđāļāļĨāđ SSL Certificate āđāļāļĒāļąāļ vCenter , VMCenter
- āļāļ Browse File : domain.crt
- āļāļ Browser File : CARootCertificate.crt
- āļāļ Browse File : private.key
āļāļāļāļļāđāļĄ Replace āļĢāļ°āļāļāļāļ°āđāļāđāđāļ§āļĨāļē reload certificate 2-5 āļāļēāļāļĩ
āļŦāļĨāļąāļāļāļēāļāļĒāļ·āļāļĒāļąāļ vCenter āļāļ°āļāļģāļāļēāļĢ restart service āđāļāļ·āđāļāđāļāđāļāļēāļ certificate
āļāđāļēāļāļŠāļēāļĄāļēāļĢāļāđāļāđāļēāđāļāđāļāļēāļāļāđāļēāļ https://{āđāļāđāļĄāļāļāļąāļāļāļēāļĢ-vcenter} āļāļāļāļāđāļēāļāđāļāđāļāļąāļāļāļĩ
Â
Â
āļ āļēāļĐāļēāļāļąāļāļāļĪāļĐ
How to Configure vCenter with CA signed instance certificate
- Log in to vCenter and go to Menu > Administration > Certificates > Certificate Management.
- Under Machine SSL Certificate, click Actions > Generate Certificate Signing Request (CSR).
- Enter the settings to generate a CSR. Leave Common name and host as default.
- Sign the CSR with a trusted third-party signing authority (for example, a CA).
- Return to vCenter, and under Machine SSL Certificate > Actions, select Import and Replace Certificate.
- On the menu that appears, select Replace with certificate generated from vCenter server.
- On the following page, click BROWSE FILE under Machine SSL Certificate and select the signed certificate.
- Click BROWSE FILE under Chain of trusted root certificates and upload the chain of trusted certificates or CA certificate file.
- Click REPLACE and confirm that the certificate has been successfully uploaded (no errors back on the Certificate Management page). vCenter may reboot.
- vCenter must be deployed with an FQDN.
- Ensure vCenter is synchronized with an NTP server.
- Users can create their own CSRs, but then must also provide the certificate key.
- After uploading a new certificate, vCenter might log the user out. If getting an error upon a refresh, try restarting vCenter or the vCenter's management network.
āļāđāļēāļāļāļīāļ
https://kb.vmware.com/s/article/2097936
https://infohub.delltechnologies.com/l/dell-validated-design-security-configurations-for-edge-solutions-using-vmware-vsphere-7-0-1/test-5-configure-vcenter-with-ca-signed-instance-certificate
Â
āļŠāļģāļŦāļĢāļąāļāļāļēāļĢāļŠāļāļąāļāļŠāļāļļāļ āđāļĨāļ°āļāđāļ§āļĒāđāļŦāļĨāļ·āļ
http://www.ireallyhost.com/support
Â
Â
Â
Â
** āļāļāļāļ§āļēāļĄāļāļĩāđāļĄāļĩāļĨāļīāļāļŠāļīāļāļāļīāđ āđāļĄāđāļāļāļļāļāļēāļāļīāđāļŦāđāļāļąāļāļĨāļāļ āļāļģāļāđāļģ āļāļąāļāđāļāļĨāļāļāđāļāļāđāļāđāļĢāļąāļāļāļāļļāļāļēāļ **
āđāļāļĢāļāļĢāļ°āļāļļāđāļŦāļĨāđāļāļāļĩāđāļĄāļē āļāļĢāļīāļĐāļąāļ āđāļāđāļāļāđāļāļĢāđāļē āļāļāļĢāđāļāļāđāļĢāļāļąāđāļ āļāļģāļāļąāļ / https://www.ireallyhost.com