Replace VCF Component Certificates with a Microsoft CA

HOMELAB JOURNAL

Replace VCF Component Certificates with a Microsoft CA

Follow VCF CA certificate replacement in Fleet Management. Generate a CSR and replace a component certificate using a configured Microsoft CA.

Overview

This VCF CA certificate replacement walkthrough starts after the Microsoft CA connection is configured. I use Fleet Management to select a component, generate its CSR and replace the certificate, then allow the inventory to refresh.

Before and after certificate replacement

  • Confirm the CA configuration succeeded at the scope containing the component. Verify the intended FQDN, SANs, subject values, issuing chain and validity period before generating the CSR.
  • Have a current supported backup, protected recovery credentials and a maintenance window. A service restart can interrupt UI/API access; changing the issuing CA can also affect trust between components.
  • Select the certificate matching the component FQDN rather than a similarly named entry. The unclear first screenshot has been removed; use the selection instructions below.
  • After completion, reconnect through the FQDN and inspect the served certificate: expected issuer, matching SAN, current validity and trusted chain.
  • Wait for inventory refresh, confirm component health and integration collection, and review any failed task. Do not repeat replacement merely because the display has not refreshed.

Select the component and generate a CSR

We can now begin deploying external CA certificates to the VCF components. At the VCF Management screen, click the radio button next to the fleet management component. You will see there are 2 listings for fleet management, ensure you click the radio button for the certificate that matches the FQDN of the fleet manager.

Click the 3 dots above the components and click Generate CSR

Input the required information for the certificate signing request and click Save

Generate CSR dialog requests certificate subject details, host and subject alternative names, with a 2048-bit key size.

A notification will appear after the CSR generation is successful at the top.

Replace the certificate

Click the 3 dots again and click Replace With Configured CA Certificate

A pop-up will appear to confirm that you want to replace the certificate with a Microsoft CA certificate. Click Confirm.

Microsoft CA replacement confirmation warns that changing the certificate authority may disrupt operation.

The certificate deployment process will start.

It will take some time to deploy this certificate as it requires service restarts on the fleet manager.

Green notification confirms certificate replacement succeeded; changes may take time to appear.

Allow the inventory to refresh

After the certificate replacement has completed, it will take time for the changes to be reflected in VCF Operations.

Repeat the process above for each individual component within VCF to replace the self-signed certificates that we created during deployment.

Related lab guides

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.