When you change the root password for a VMware Cloud Director appliance, you must also update the appliance certificate keystore to use the new password.



  1. Log in directly or by using an SSH client to the VMware Cloud Director appliance console as root.
  2. Run the passwd command and change the password for the root user.
    passwd root
    Note: If the root password is already expired, VMware Cloud Director prompts you to set it the first time when you log in to the VMware Cloud Director appliance console as root.
  3. Run the command to back up the existing certificates keystore file.
    cp /opt/vmware/vcloud-director/certificates.ks /tmp/certificates.ks
  4. To generate a new certificates keystore, run the keytool command.
    keytool -importkeystore -srckeystore /opt/vmware/vcloud-director/certificates.ks -srcstoretype PKCS12 -srcstorepass old_root_password -destkeystore /opt/vmware/vcloud-director/certificates-new.ks -deststoretype PKCS12 -deststorepass new_root_password 
    -destkeypass new_root_password
    Starting with VMware Cloud Director 10.2, the default certificate keystore type for the VMware Cloud Director appliance is PKCS12. If you are using a version of the appliance that was upgraded to version 10.2, use JCEKS as the -srcstoretype and -deststoretype.
    keytool -importkeystore -srckeystore /opt/vmware/vcloud-director/certificates.ks -srcstoretype JCEKS -srcstorepass old_root_password -destkeystore /opt/vmware/vcloud-director/certificates-new.ks -deststoretype JCEKS -deststorepass new_root_password 
    -destkeypass new_root_password
  5. Run the command to replace the old certificates keystore file with the new one.
    mv /opt/vmware/vcloud-director/certificates-new.ks /opt/vmware/vcloud-director/certificates.ks
  6. To verify the user and group ownership of the keystore file, run the chown command.
    chown vcloud.vcloud /opt/vmware/vcloud-director/certificates.ks
  7. To use the keystore's new password, update the VMware Cloud Director server configuration:
    /opt/vmware/vcloud-director/bin/cell-management-tool certificates -j -p --keystore /opt/vmware/vcloud-director/certificates.ks --keystore-password new_root_password

What to do next

Repeat this procedure on each appliance in the cluster.
Important: All appliances must share the same root password. Any newly deployed appliance must use the new root password.