GreatWhiteTec
VMware Employee
VMware Employee

Hi vHaridas,

Is this test only or prod? If test only, you can reset your KMS server to delete the old certs, which still count against the total number of certs. You can remove all keys by resetting the KMIP server. Go to Settings -> KMIP Server Settings, then click the "Reset KMIP Server" button. This will remove all keys on HyTrust, so DO NOT DO THIS ON PRODUCTION SERVER!. After the reset, Change state to "Enabled", and click the "Apply" button.

In VC, you should be able to see the certs in the UI. Administration>System Configuration>nodes. Select VC>Manage>Certificate Authority.

AFAIK, VMCA uses OpenSSL, so I'm assuming it gets the limits from it.

Reply
0 Kudos