A VMware Endpoint Certificate Store (VECS) instance is included on each Platform Services Controller node and each vCenter Server node. You can explore the different stores inside the VMware Endpoint Certificate Store from the Platform Services Controller web interface.

See VMware Endpoint Certificate Store Overview for details on the different stores inside VECS.


For most management tasks, you must have the password for the administrator for the local domain account, administrator@vsphere.local or a different domain if you changed the domain during installation.


  1. From a Web browser, connect to the Platform Services Controller by specifying the following URL:
    In an embedded deployment, the Platform Services Controller host name or IP address is the same as the vCenter Server host name or IP address.
  2. Specify the user name and password for administrator@vsphere.local or another member of the vCenter Single Sign-On Administrators group.
    If you specified a different domain during installation, log in as administrator@ mydomain.
  3. Under Certificates, click Certificate Store and explore the store.
  4. Select the store inside the VMware Endpoint Certificate Store (VECS) that you want to explore from the pulldown menu.
    VMware Endpoint Certificate Store Overview explains what's in the individual stores.
  5. To view details for a certificate, select the certificate and click the Show Details icon.
  6. To delete an entry from the selected store, click the Delete Entry icon.
    For example, if you replace the existing certificate, you can later remove the old root certificate. Remove certificates only if you are sure that they are no longer in use.