Many companies only require that you replace certificates of services that are accessible externally. However, Certificate Manager also supports replacing solution user certificates. Solution users are collections of services, for example, all services that are associated with the vSphere Client.

When you are prompted for a solution user certificate, provide the complete signing certificate chain of the third-party CA.

The format looks similar to the following.
Signing certificate
CA intermediate certificates
Root certificate of enterprise or external CA


Before you start, you need a CSR for each machine in your environment. You can generate the CSR using vSphere Certificate Manager or explicitly.

  1. To generate the CSR using vSphere Certificate Manager, see Generate Certificate Signing Requests with vSphere Certificate Manager (Custom Certificates).
  2. Request a certificate for each solution user on each node from your third-party or enterprise CA. You can generate the CSR using vSphere Certificate Manager or prepare it yourself. The CSR must meet the following requirements:
    • Key size: 2048 bits (minimum) to 16384 bits (maximum) (PEM encoded)
    • CRT format
    • x509 version 3
    • SubjectAltName must contain DNS Name=<machine_FQDN>.
    • Each solution user certificate must have a different Subject. Consider, for example, including the solution user name (such as vpxd) or other unique identifier.

    • Contains the following Key Usages: Digital Signature, Key Encipherment

See also the VMware knowledge base article at, Obtaining vSphere certificates from a Microsoft Certificate Authority.


  1. Start vSphere Certificate Manager and select option 5.
  2. Select option 2 to start certificate replacement and respond to the prompts.
    vSphere Certificate Manager prompts you for the following information:
    • Password for administrator@vsphere.local
    • Certificate and key for machine solution user
    • The certificate and key (vpxd.crt and vpxd.key) for the machine solution user
    • The full set of certificates and keys (vpxd.crt and vpxd.key) for all solution users