Replace the default or expired certificate on the ESXi host. Use the CertGenVVD utility to generate the certificates. Procedure Set Host Certificate Mode on the Management vCenter Server to Support a Custom Certificate Authority in Region BBy default, the ESXi hosts are automatically provisioned with VMware Certificate Authority (VMCA) certificates when they are connected to vCenter Server. Set the host certificate mode on vCenter Server in Region B to support a custom certificate authority so that vCenter Server stops pushing VMCA certificates on to the ESXi hosts. Replace the Default Certificate with a Custom Certificate on the Management ESXi Hosts in Region BAfter you obtain signed certificates for the ESXi hosts in Region B and configure vCenter Server to accept customer certificate authorities, replace the default VMware Certificate Authority (VMCA) signed certificates on the hosts. Configure Certificate Mode for and Replace Certificates on the Hosts in the Shared Edge and Compute Cluster in Region BAfter you replace the certificates of the ESXi hosts in the management cluster, complete certificate replacement in Region B on the hosts in the shared edge and compute cluster. Parent topic: Replace Certificates of the Virtual Infrastructure Components in Region B Previous topic: Replace vCenter Server Certificates in Region B Next topic: Replace the NSX Manager Certificates in Region B