You can replace the default VMCA-signed ESXi certificates with the vifs command.
Prerequisites
- If you want to use third-party CA-signed certificates, generate the certificate request, send it to the certificate authority, and store the certificates on each ESXi host.
- If necessary, enable the ESXi Shell or enable SSH traffic from the vSphere Web Client. See the vSphere Security publication for information on enabling access to the ESXi Shell.
- All file transfers and other communications occur over a secure HTTPS session. The user who is used to authenticate the session must have the privilege on the host. See the vSphere Security publication for information on assigning privileges through roles.
Procedure
What to do next
Update the vCenter Server TRUSTED_ROOTS store. See Update the vCenter Server TRUSTED_ROOTS Store (Custom Certificates).