<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VCenter Server Certificate Change in vCenter™ Server Discussions</title>
    <link>https://communities.vmware.com/t5/vCenter-Server-Discussions/VCenter-Server-Certificate-Change/m-p/2305188#M75699</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe your&amp;nbsp; vcenter machine is deployed with ip deployment &lt;/P&gt;&lt;P&gt;if there is an IP deployment, the PNID is set as IP address. You have two options &lt;/P&gt;&lt;P&gt;1.Change pnid to FQDN instead of ip and replace with same cert - &lt;A href="https://blogs.vmware.com/vsphere/2019/08/changing-your-vcenter-servers-fqdn.html" title="https://blogs.vmware.com/vsphere/2019/08/changing-your-vcenter-servers-fqdn.html"&gt;Changing your vCenter Server's FQDN - VMware vSphere Blog&lt;/A&gt; &lt;/P&gt;&lt;P&gt;2. Include ip address in Subject alternative name and proceed to change cert (keeping pnid as ip)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Aug 2020 12:19:49 GMT</pubDate>
    <dc:creator>msripada</dc:creator>
    <dc:date>2020-08-07T12:19:49Z</dc:date>
    <item>
      <title>VCenter Server Certificate Change</title>
      <link>https://communities.vmware.com/t5/vCenter-Server-Discussions/VCenter-Server-Certificate-Change/m-p/2305187#M75698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I hope everyone in the community is keeping safe during these changing times.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am currently experiencing an issue with my VCenter Server 7.0 that I have deploy in my Environment. I am attempting to change the Machine_Cert with one that is signed by my internal certificate auth. Every time I attempt to change the certificate I get the following error '&lt;SPAN style="color: #e9ecef; font-family: Metropolis, 'Avenir Next', 'Helvetica Neue', Arial, sans-serif; font-size: 13px; background-color: #882d31;"&gt;Error occurred while fetching tls: Exception found (Invalid input certificate : DNS in Subject Alternative Name is not correct. DNS Name must contain machine FQDN.).&lt;/SPAN&gt;&lt;/P&gt;&lt;H6&gt;&lt;SPAN style="color: #e9ecef; font-family: Metropolis, 'Avenir Next', 'Helvetica Neue', Arial, sans-serif; font-size: 13px; background-color: #882d31;"&gt; &lt;/SPAN&gt;&lt;/H6&gt;&lt;P&gt;I have made sure that I am including the vcenter server hostname in the Subject Alternative Name so should all be working as expected. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CN = 172.16.0.30&lt;/P&gt;&lt;P&gt;Subject Alternatives that are included&lt;/P&gt;&lt;P&gt;DNS = vcserver.domain.local&lt;/P&gt;&lt;P&gt;DNS = vcserver&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I run the following command I get the output of 172.26.0.30 from my server. &lt;/P&gt;&lt;P&gt;'root@vcserver [ ~ ]# /usr/lib/vmware-vmafd/bin/vmafd-cli get-pnid --server-name localhost'&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;172.26.0.30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also compared the currently used Subject Alternatives to what is in my new certificate and these are the same. Has anyone seen this issue before or able to help out with fixing the issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Aug 2020 18:43:33 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCenter-Server-Discussions/VCenter-Server-Certificate-Change/m-p/2305187#M75698</guid>
      <dc:creator>Teparky</dc:creator>
      <dc:date>2020-08-06T18:43:33Z</dc:date>
    </item>
    <item>
      <title>Re: VCenter Server Certificate Change</title>
      <link>https://communities.vmware.com/t5/vCenter-Server-Discussions/VCenter-Server-Certificate-Change/m-p/2305188#M75699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe your&amp;nbsp; vcenter machine is deployed with ip deployment &lt;/P&gt;&lt;P&gt;if there is an IP deployment, the PNID is set as IP address. You have two options &lt;/P&gt;&lt;P&gt;1.Change pnid to FQDN instead of ip and replace with same cert - &lt;A href="https://blogs.vmware.com/vsphere/2019/08/changing-your-vcenter-servers-fqdn.html" title="https://blogs.vmware.com/vsphere/2019/08/changing-your-vcenter-servers-fqdn.html"&gt;Changing your vCenter Server's FQDN - VMware vSphere Blog&lt;/A&gt; &lt;/P&gt;&lt;P&gt;2. Include ip address in Subject alternative name and proceed to change cert (keeping pnid as ip)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Aug 2020 12:19:49 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCenter-Server-Discussions/VCenter-Server-Certificate-Change/m-p/2305188#M75699</guid>
      <dc:creator>msripada</dc:creator>
      <dc:date>2020-08-07T12:19:49Z</dc:date>
    </item>
    <item>
      <title>Re: VCenter Server Certificate Change</title>
      <link>https://communities.vmware.com/t5/vCenter-Server-Discussions/VCenter-Server-Certificate-Change/m-p/2960687#M94224</link>
      <description>&lt;P&gt;I dont think you can include the short name as a SAN. I have come accross the same problem&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;CN was FQDN&lt;/P&gt;&lt;P&gt;SANs included IP and shortname&lt;/P&gt;&lt;P&gt;Removed SANs as not essential for us&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 18:46:38 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/vCenter-Server-Discussions/VCenter-Server-Certificate-Change/m-p/2960687#M94224</guid>
      <dc:creator>burchell99</dc:creator>
      <dc:date>2023-03-23T18:46:38Z</dc:date>
    </item>
  </channel>
</rss>

