VMware Cloud Community
brn2015
Contributor
Contributor
Jump to solution

How can I change the certificate for the VAMI on VCSA 6.5?

Hi! I am currently using the VCSA 6.5. I was able to change the machine certificates to signed certificates using the certificate-manager tool set in the CLI.

I notice when I go to access the VMware Appliance Manager its still using a self-signed cert.

How can I change this cert as well? I cannot find instructions on how to change that particular cert, only the machine certs.

Thanks!

0 Kudos
1 Solution

Accepted Solutions
brn2015
Contributor
Contributor
Jump to solution

So I called support and basically after installing the machine certificate service-control --stop --all does not stop the vami-lighttp service. The VAMI certificate will be updated only after restarting the service. Restart the service manually made the VAMI service to pickup the new certificate chain.

Guess you have to restart. Looks like this is a bug targeted for fixing (with a new certificate manager) in u3.

View solution in original post

0 Kudos
4 Replies
guruswapanvi
VMware Employee
VMware Employee
Jump to solution

Hi,

Did you changed the Machine SSL certificate or Machine (Solution user) certificate?

Thanks!

0 Kudos
brn2015
Contributor
Contributor
Jump to solution

I changed the Machine SSL certificate.

0 Kudos
brn2015
Contributor
Contributor
Jump to solution

So I called support and basically after installing the machine certificate service-control --stop --all does not stop the vami-lighttp service. The VAMI certificate will be updated only after restarting the service. Restart the service manually made the VAMI service to pickup the new certificate chain.

Guess you have to restart. Looks like this is a bug targeted for fixing (with a new certificate manager) in u3.

0 Kudos
MotisLtd
Contributor
Contributor
Jump to solution

The service restart didn't work for me, but this procedure did:

https://kb.vmware.com/s/article/2136693

0 Kudos