Certificate authority privileges control aspects of VMware Certificate Authority (VMCA) certificates.

Table 1. Certificate Authority Privileges
Privilege Name in the vSphere Client Description Required On Privilege Name in the API
Create/Delete (Admins priv).

Allows full administrative-level access for managing vCenter Server certificates.

vCenter Server CertificateAuthority.Administer
Create/Delete (below Admins priv). Allows viewing the VMCA root certificate in the Certificate Management page in the vSphere Client. vCenter Server CertificateAuthority.Manage