charlespick's Posts

I downloaded and loaded the root VMCA certificate into my system's certificate store today and trusted it. Now going to my vsphere web client and the vcenter server management portal presents no cert... See more...
I downloaded and loaded the root VMCA certificate into my system's certificate store today and trusted it. Now going to my vsphere web client and the vcenter server management portal presents no certificate warnings in Chrome. While I don't love using non root verified certs like this, I'd be ok if it at least worked for my ESXi hosts as well. Unfortunately it's provisioning certificates for more than 13 months for the ESXi hosts causing a certificate valid too long error. So far I haven't found a way to change that time frame.  If that isn't possible then I'd like to manage all my certificates manually, I only have 3 hosts + vCenter so it's not too much to handle and I have a 3rd party CA already. I set the vpxd.certmgmt.mode in my vSphere to custom and rebooted my vSphere and an ESXi host but I'm still getting the message "This host's certificates are being managed by vCenter Server, you cannot configure them using the Host Client." 
I wasn't aware that most people just leave it as vsphere.local and thought that you're supposed to change it. 
I deployed vCenter Server and setup the local SSO domain as lets say domain.com My Windows Server based Active Directory is also domain.com. I was able to join the vCenter server to the domain but w... See more...
I deployed vCenter Server and setup the local SSO domain as lets say domain.com My Windows Server based Active Directory is also domain.com. I was able to join the vCenter server to the domain but when trying to add it as an identity source, it's complaining that domain.com is already taken. I can't delete the domain.com local sso identity provider because I'm using it to login. I can't figure out how to use the localos root account to login to vsphere web client. So what do I have to do? Should I just redeploy with a different name and then setup active directory again? Charles