Replacing Directory Services Certs with Load Balanced vCenter 6 External PSCs


I am trying to get some help with the process of replacing the Directory Services certificates on the PSC's in a load balanced scenario.

I am using the "custom" method, and have replaced every other certificate in the environment without issue.

I have the process/steps to replace the certificate on an individual PSC, but am unsure how this translates in to a load balanced environment with 2 x PSCs.

Do I replace the certificate on both PSCs and treat them as separate devices, each having a certificate with their own FQDN.

Or do I replace the certs on both of them with a cert using the FQDN of the load balancer?

Any help would be appreciated.


