Tasks: replace CA signed SSL certificate on ESXi hosts
as you know, in part 1 and part 2, I cerated rui.key and rui.csr files and sent csr file to security team for the CA sign.
Today I received rui.crt file them and going to replace it with below stepts
before I'm going to replace, I verified the exiting SSL certificate expire date by web browser (https://ESXIhostname)
data:image/s3,"s3://crabby-images/b37fb/b37fb52df8f9c5681a61f3153b8a80197913a56f" alt=""
data:image/s3,"s3://crabby-images/4ffca/4ffca9bb936541ebb657bd52bb8954e760aa70d8" alt=""
1) using winSCP or some other method, copy the rui.csr and rui.key files to esxi /temp folder
data:image/s3,"s3://crabby-images/8cd26/8cd262389d4e30110d24a9fad9368ea869b39744" alt=""
2) rename the existing SSL certifacte as orog.rui.crt and orig.rui.key
data:image/s3,"s3://crabby-images/28f5a/28f5a2350eceeb8c164a90bab5407aad1856e1a8" alt=""
3) copy the new SSL cert from temp folder to /etc/vmware/SSL folders
data:image/s3,"s3://crabby-images/cd9a0/cd9a023d1c78b085554c44bc3e6ab1c93ffe5e17" alt=""
4) in order to use new SSL, restart the management services by restart.sh restart or /etc/init.d/vpxa restart and /etc/init.d/hostd restart
5) once restarted, re-connect the host back to vcenter and verify the SSL certificate on web browser.
data:image/s3,"s3://crabby-images/6847a/6847a5a05ff1e34b91995407e72a931687c8b7c4" alt=""
as you know, in part 1 and part 2, I cerated rui.key and rui.csr files and sent csr file to security team for the CA sign.
Today I received rui.crt file them and going to replace it with below stepts
before I'm going to replace, I verified the exiting SSL certificate expire date by web browser (https://ESXIhostname)
1) using winSCP or some other method, copy the rui.csr and rui.key files to esxi /temp folder
2) rename the existing SSL certifacte as orog.rui.crt and orig.rui.key
3) copy the new SSL cert from temp folder to /etc/vmware/SSL folders
4) in order to use new SSL, restart the management services by restart.sh restart or /etc/init.d/vpxa restart and /etc/init.d/hostd restart
5) once restarted, re-connect the host back to vcenter and verify the SSL certificate on web browser.