Academy/VCAP — VCF Administrator (3V0-11.26)/Lab: Certificate Lifecycle — VMCA Subordinate CA & Rotation
This lab targets VCF 9.0

Lab: Certificate Lifecycle — VMCA Subordinate CA & Rotation

VCF 9.0Advancedvcap-advanced⏱ 120 min

Certificate management: VMCA subordinate CA, certificate rotation, expiry monitoring

Objectives

  • Configure VMCA as a subordinate CA under enterprise PKI
  • Perform certificate rotation for vCenter and ESXi hosts
  • Monitor certificate health using VCF Operations alerts
  • Troubleshoot certificate trust chain issues
  • Implement a certificate lifecycle management process

Prerequisites

VCF 9.0 Instance operational, enterprise CA available (or OpenSSL lab CA for testing), SSH access to vCenter appliance

Required skills:

  • PKI/certificate concepts
  • vCenter Certificate Manager
  • OpenSSL basics

Lab Environment

VCF 9.0 with vCenter and 2+ ESXi hosts. Enterprise CA (Active Directory Certificate Services, HashiCorp Vault, or OpenSSL lab CA) accessible from vCenter.

Tasks

Task 1 VMCA Subordinate CA Configuration & Certificate Rotation

VMCA subordinate mode is the VMware-recommended production configuration. It provides: enterprise PKI trust chain (browsers/clients trust VCF certificates), automated leaf certificate issuance (VMCA handles ESXi, solution users), and centralized certificate governance. Custom mode (manually replacing each certificate) is labor-intensive and error-prone — avoid unless required by policy.

Transform VMCA from self-signed root to enterprise CA subordinate, then perform certificate rotation across VCF components — the most common certificate operation in production VCF environments.

Step 1
Pre-flight: Audit current certificate state. SSH to vCenter → /usr/lib/vmware-vmafd/bin/vecs-cli store list → lists all certificate stores. For each store: vecs-cli entry list --store <name> → shows certificates with expiry dates. Alternatively: vCenter UI → Administration → Certificate Management → overview. Document current state: VMCA root cert expiry, machine SSL cert expiry, solution user cert expiry.
Step 2
Generate VMCA subordinate CSR. SSH to vCenter → /usr/lib/vmware-vmca/bin/certificate-manager → Option 2: 'Replace VMCA Root Certificate with Custom Signing Certificate'. Follow prompts to generate a CSR. The CSR includes VMCA's public key and subject information. Save the CSR file — you'll submit it to the enterprise CA.
Step 3
Sign CSR with enterprise CA. Submit the CSR to your enterprise CA: (a) For AD CS: Web enrollment → Advanced Certificate Request → paste CSR → select 'Subordinate Certification Authority' template → Submit. (b) For OpenSSL lab CA: openssl x509 -req -in vmca.csr -CA ca.crt -CAkey ca.key -CAcreateserial -out vmca-signed.crt -days 3650 -extfile vmca-ext.cnf (with basicConstraints=CA:TRUE, keyUsage=keyCertSign,cRLSign). Download the signed certificate and CA chain.
Step 4
Import signed certificate into VMCA. Return to certificate-manager → provide the signed VMCA certificate and the CA chain (root CA + any intermediate CAs). Certificate-manager: (a) replaces the VMCA root with the signed subordinate certificate, (b) automatically re-issues all leaf certificates (Machine SSL, solution users) signed by the new VMCA. This process takes 5-10 minutes. vCenter services restart automatically.
Step 5
Verify certificate chain. After vCenter services restart: (a) browse to vCenter UI — browser should show trusted certificate (green lock) if enterprise CA is in the browser trust store; (b) SSH to vCenter: openssl s_client -connect localhost:443 -showcerts → verify chain: leaf cert → VMCA subordinate → enterprise root CA; (c) Check ESXi hosts: vCenter → Host → Configure → Certificate → should show 'Issued by: VMCA' with new dates.
Step 6
Rotate ESXi host certificates. vCenter → Host → Configure → Certificate → Renew. vCenter contacts VMCA, generates a new leaf certificate for the host, and installs it. The host remains operational — no reboot required. Repeat for all hosts. For bulk rotation: use the vSphere API (POST /rest/vcenter/certificate-management/vcenter/tls) or VCF LCM certificate update workflow.
Step 7
Configure certificate expiry monitoring. VCF Operations → alert definition → create symptom: 'Certificate Days to Expiry < 60'. Alert definition: 'Certificate-Expiry-Warning' → Criticality=Warning. Notification: email to security-team@lab.local. Create a second alert at 30 days with Criticality=Critical. This proactive monitoring prevents certificate-related outages (expired certificates cause service communication failures).
Step 8

Test certificate trust. From a client machine: (a) curl -v https://<vcenter-fqdn> — verify TLS handshake succeeds without certificate warnings; (b) PowerCLI: Connect-VIServer <vcenter> — should connect without -Force parameter (trusted cert); (c) REST API: curl https://<vcenter>/rest/vcenter/vm — no certificate error. If trust fails: import the enterprise root CA certificate into the client trust store.

Step 9

Document certificate lifecycle runbook. Record: (a) VMCA subordinate CA configuration procedure with screenshots; (b) certificate rotation schedule (annual recommended); (c) emergency rotation procedure (for compromised certificate); (d) certificate chain: list all CAs in the trust chain with expiry dates; (e) monitoring: alert thresholds and notification channels. This documentation is a VCAP exam deliverable and a production operations requirement.

Step 10

Rollback test. In a lab environment, test rollback: revert VMCA to self-signed root using certificate-manager Option 4 (Reset all certificates). Observe: (a) all leaf certificates are re-issued with self-signed VMCA root; (b) browser shows untrusted certificate again; (c) existing API integrations may break (they trusted the enterprise chain). This validates your rollback procedure without affecting production.

Validation Gate

Check: VMCA subordinate CA operational with trusted certificate chain

Expected: VMCA configured as subordinate CA, all leaf certificates re-issued, browser shows trusted connection, ESXi certificates rotated, expiry monitoring configured, rollback procedure validated

Common Errors

certificate-manager fails with 'Certificate chain validation error'
Fix: The CA chain file must include ALL intermediate CAs between the VMCA subordinate cert and the root CA, in order from subordinate to root. Verify with: openssl verify -CAfile ca-chain.pem vmca-signed.crt. Missing intermediates are the most common cause.
vCenter services fail to start after certificate replacement
Fix: Certificate format issue — VMCA requires PEM format (not DER or PKCS12). Verify: openssl x509 -in vmca-signed.crt -text -noout should display certificate details. If services fail: restore from snapshot (this is why pre-flight snapshot is mandatory).
ESXi hosts disconnect after VMCA replacement
Fix: Host certificates are still signed by the old VMCA root. vCenter should auto-renew them, but if connectivity was interrupted during the process, manual renewal is needed: Host → Certificate → Renew. If host is disconnected: reconnect first, then renew.
API integrations break after certificate change
Fix: External tools (monitoring, backup, automation) that pinned the old certificate or CA need to be updated to trust the new enterprise CA chain. Update trust stores in all integration points.

Final Validation

Certificate lifecycle management operational with enterprise CA integration

✓ VMCA subordinate → VMCA signed by enterprise CA, leaf certs chain to enterprise root

✓ Browser trust → vCenter UI shows trusted certificate (green lock)

✓ ESXi certificates → All hosts show renewed certificates issued by VMCA

✓ Expiry monitoring → Alerts configured at 60-day and 30-day thresholds

✓ API trust → REST API and PowerCLI connect without certificate errors

Cleanup / Restore

• Delete pre-change snapshots after 48 hours of stable operation

• Document the certificate chain in the CMDB

• Schedule annual certificate rotation reminder

Design Reflection (VCDX)

Certificate management is a frequent VCDX defense topic. Key arguments: (1) VMCA subordinate mode balances enterprise PKI governance with operational simplicity — VMCA handles leaf cert automation; (2) Certificate monitoring prevents the #1 cause of VCF service outages (expired certs); (3) Document the full trust chain and rotation schedule as operational deliverables.

Requirements

  • Enterprise-trusted certificates on all VCF management interfaces
  • Proactive expiry monitoring with 60-day warning
  • Annual certificate rotation capability without service outage

Constraints

  • VMCA subordinate cert must have CA:TRUE basicConstraint
  • Certificate-manager requires vCenter services restart (brief API unavailability)
  • Custom mode (non-VMCA) requires manual rotation of 10+ certificates per vCenter

Assumptions

  • Enterprise CA is available and can sign subordinate CA requests
  • Enterprise root CA is in all client trust stores (browsers, API tools)
  • vCenter snapshot taken before certificate operations

Risks

  • Failed certificate replacement leaves vCenter in inconsistent state — snapshot rollback is the safety net
  • Expired enterprise root CA invalidates entire VCF certificate chain
  • Certificate rotation without updating external integrations causes monitoring/backup failures

Self-Assessment Discussion Prompts

  1. When would you choose custom mode over VMCA subordinate mode?
  2. How do you handle certificate rotation in a VCF Instance with 10+ vCenters?
  3. What is the blast radius of an expired VMCA subordinate certificate?

Extensions

Automate certificate rotation using the vSphere Certificate Management API

Configure HashiCorp Vault as an external CA for VCF certificate operations

Build a certificate health dashboard in VCF Operations showing all cert expiry dates

⚠ Known Pitfalls (from Community KB)

Not taking a vCenter snapshot before certificate operations — failed cert replacement is difficult to recover without snapshot
Submitting VMCA CSR to enterprise CA with wrong template (must be Subordinate CA, not Web Server)
Forgetting to renew ESXi host certificates after VMCA replacement — hosts continue with old certs until explicit renewal
Using certificate-manager during active VCF lifecycle operations — wait for all tasks to complete first

References

  • vSphere 8.0 Security Guide — Certificate Management: techdocs.broadcom.com
  • VCF 9.0 Certificate Lifecycle Guide: techdocs.broadcom.com
Was this page useful?
Type to search. ↑ ↓ to move, Enter to open, Esc to close.