VMware Cloud Community
sungpillhan2
Enthusiast
Enthusiast

STS Signing Certificates are about to expire - vCenter 7

 

Environment:

ESXI 6.5, vCenter  7.0.1

 

Hello Experts, 

I need your help on two certificate issues. 

  1.  I received alert on vCenter "STS Signing Certificates are about to expire"

So I tried to follow below, but there's no STS signing certificate, but only Machine and CA certificates. 

 I have no issue signing into vCenter. Any idea? 

"STS Signing Certificates are about to expire" alert received in vSphere UI (83558) https://kb.vmware.com/s/article/83558?lang=en_US

certscerts

I ran checksts.py and shows it will expire in 78 days. I am not sure if I need to run fixsts.py because the cert doesn't show in GUI at all. ..

 

b.png

 

2. Machine cert is about to expire.

When machine cert expires, what's the impact? 

How do I renew before it expires? will the steps to renew need to be in maintenance window?

 

Thank you in advance

Reply
0 Kudos
5 Replies
sungpillhan2
Enthusiast
Enthusiast

Hello, 

I was able to update STS and Machine certificates. 

Then, I listed all certificates in vCenter and see multiple certificates expiring on 2022. Are they not being used or need to renew as well? If yes, how do I update them?

 

2022-04-26 15_45_42-mRemoteNG - confCons.xml - vCenter`.png

Reply
0 Kudos
Vijay2027
Expert
Expert

You will have to use option 6 to reset solution user certificates. 

Expiry on back-up store can be ignored or if you want to clean-up follow https://kb.vmware.com/s/article/82560

Reply
0 Kudos
Ajay1988
Expert
Expert

STS HTML UI administration started with 7.0 U3 only. 

 

This KB is for sts replacement https://kb.vmware.com/s/article/76719  . But it does have inputs for other certs.

Ajay1988_0-1651216978612.png

 

If you think your queries have been answered
Mark this response as "Correct" or "Helpful".

Regards,
AJ
Reply
0 Kudos
NAIKAKASH
Contributor
Contributor

Instead of option 6 , I believe fixsts script should be use to generate new STS certificate.

Ref : https://kb.vmware.com/s/article/79263

Reply
0 Kudos
mannharry
Hot Shot
Hot Shot

Reply
0 Kudos