<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Validity Period of VMCA Certificates in VMware vSphere™ Discussions</title>
    <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/Validity-Period-of-VMCA-Certificates/m-p/939648#M11077</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure, the parameter is vpxd.certmgmt.certs.daysValid under vCenter Server &amp;gt; Configure &amp;gt; Advanced Settings&lt;span class="lia-inline-image-display-wrapper" image-alt="2018-04-26_15-08-35.png"&gt;&lt;img src="https://communities.vmware.com/t5/image/serverpage/image-id/81424i97B6D755CCF72299/image-size/large?v=v2&amp;amp;px=999" role="button" title="2018-04-26_15-08-35.png" alt="2018-04-26_15-08-35.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 26 Apr 2018 19:10:15 GMT</pubDate>
    <dc:creator>vmEck</dc:creator>
    <dc:date>2018-04-26T19:10:15Z</dc:date>
    <item>
      <title>Validity Period of VMCA Certificates</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/Validity-Period-of-VMCA-Certificates/m-p/939646#M11075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For certificates that are issued from the VMCA (talking 6.0/6.5), is there a way to specify the maximum validity period of the certificate that the VMCA hands out? Just wondering if this can be adjusted lower.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Apr 2018 23:33:39 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/Validity-Period-of-VMCA-Certificates/m-p/939646#M11075</guid>
      <dc:creator>mamoth100</dc:creator>
      <dc:date>2018-04-25T23:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Validity Period of VMCA Certificates</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/Validity-Period-of-VMCA-Certificates/m-p/939647#M11076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you're making the VMCA a sub-CA, then you should able to specify that in the issuing CA's delegation cert. Otherwise, for just internal issuance, I'm not sure there's a parameter that controls such behavior.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2018 16:46:47 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/Validity-Period-of-VMCA-Certificates/m-p/939647#M11076</guid>
      <dc:creator>daphnissov</dc:creator>
      <dc:date>2018-04-26T16:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Validity Period of VMCA Certificates</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/Validity-Period-of-VMCA-Certificates/m-p/939648#M11077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure, the parameter is vpxd.certmgmt.certs.daysValid under vCenter Server &amp;gt; Configure &amp;gt; Advanced Settings&lt;span class="lia-inline-image-display-wrapper" image-alt="2018-04-26_15-08-35.png"&gt;&lt;img src="https://communities.vmware.com/t5/image/serverpage/image-id/81424i97B6D755CCF72299/image-size/large?v=v2&amp;amp;px=999" role="button" title="2018-04-26_15-08-35.png" alt="2018-04-26_15-08-35.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2018 19:10:15 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/Validity-Period-of-VMCA-Certificates/m-p/939648#M11077</guid>
      <dc:creator>vmEck</dc:creator>
      <dc:date>2018-04-26T19:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Validity Period of VMCA Certificates</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/Validity-Period-of-VMCA-Certificates/m-p/939649#M11078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks &lt;A _jive_internal="true" data-avatarid="10951" data-externalid="" data-online="false" data-presence="null" data-userid="1971993" data-username="vmEck" href="https://communities.vmware.com/people/vmEck" name="&amp;amp;amp;lpos=apps_scodevmw : 111" style="font-weight: bold; font-family: proxima-nova, Arial, sans-serif; color: inherit;"&gt;Adam Eckerle&lt;/A&gt; and &lt;B&gt;daphnissov&lt;/B&gt; !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did see this for the hosts within vCenter after posting the thread. However, there doesn't seem to be a way to control this for the PSC Machine Cert nor the cert vCenter gets from the VMCA. Once we get down to vCenter... there do seem to be controls for the hosts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm wondering if it's possible to actually do it more so on the PSC Machine certificate and the vCenter cert that it gets from the PSC. I tried today. I got the internal CA cert chain done (which has a validity period of 5 years.. as we do not expect this solution to be around in 5 years) and loaded it into the VMCA. It was successful. During that load, it goes through and issues a Machine cert to that same PSC. The cert was issues for the same validity period as the VMCA cert. And due to regulations, we need the cert validity period to be 3 years or less on all devices. What I didn't want to have happen was the VMCA certs expire at the same time the PSC Machine certs and vCenter certs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the cert... I know I had to black out the Issued By... but I can validate that it was indeed the VMCA. You can see it chucked it out to the PSC's Machine Cert as 5 years.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="pastedImage_2.png"&gt;&lt;img src="https://communities.vmware.com/t5/image/serverpage/image-id/81421iBC8C72CAFCF64FBF/image-size/large?v=v2&amp;amp;px=999" role="button" title="pastedImage_2.png" alt="pastedImage_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Apr 2018 00:39:28 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/Validity-Period-of-VMCA-Certificates/m-p/939649#M11078</guid>
      <dc:creator>mamoth100</dc:creator>
      <dc:date>2018-04-27T00:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: Validity Period of VMCA Certificates</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/Validity-Period-of-VMCA-Certificates/m-p/939650#M11079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It does appear I can force days into the CSR with openssl.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;openssl x509 -req &lt;STRONG&gt;-days 1094&lt;/STRONG&gt; -in /certs/psc_ha_vip.csr -out /certs/psc_ha_vip.crt -CA /var/lib/vmware/vmca/root.cer -CAkey /var/lib/vmware/vmca/privatekey.pem -extensions v3_req -CAcreateserial -extfile /certs/psc_ha_csr_cfg.cfg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I was able to get the PSC Machine Cert to less than 3 years. But vCenter will be the next hurdle as that will probably end up with a 5 year cert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I really wish there was a way to just tell VMCA to only issue 3 year certs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Apr 2018 02:01:27 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/Validity-Period-of-VMCA-Certificates/m-p/939650#M11079</guid>
      <dc:creator>mamoth100</dc:creator>
      <dc:date>2018-04-27T02:01:27Z</dc:date>
    </item>
  </channel>
</rss>

