VMware vSphere ESXi 8.0 Certificate Replacement via SSH

VMware vSphere ESXi 8.0 Certificate Replacement via SSH


=

Today, I had an Interesting one. As this was a new install of VMware vSphere ESXi 8.0, or at least within a few days. And low and behold, it has a expired Certificate!? This is a technical write up, with the steps I performed to fix it in my own lab.

When I logged into the Host I Saw the following.

No alt text provided for this image


That isn’t good, lets go fix it.

Step 1. Google.

I found this write up by Jesus Vigo in Security

How to regenerate certificates on VMware host servers

https://www.techrepublic.com/article/how-to-regenerate-certificates-on-vmware-host-servers/
“By default, VMware host servers, like ESXi hosts typically generate new certificates when the hypervisor is installed on bare-metal hardware. Through the process of configuring the host and allocating resources, it is common for the server configuration to undergo many settings changes as you harden your device.

However, while the process to join the server to AD may be straightforward, it can and certainly will consistently fail if the SSL certificates used by the VMware host are expired, invalid, or otherwise corrupted.

Ok, lets get to it!

First lets enable SSH, Go to Manage , Services.

No alt text provided for this image


Select TSM-SSH, Name SSH and Click start

No alt text provided for this image

Next, lets login via ssh. I used Putty.

No alt text provided for this image


Lets move to the dir that has the SSL keys to back up the keys. Per the above write up.

cd /etc/vmware/ssl

Then run the following.

mv rui.crt rui.crt.bak mv rui.key rui.key.bak

But I got the following error.

No alt text provided for this image


So we are going to move on.

Next type /sbin/generate-certificates

Then /etc/init.d/hostd restart

No alt text provided for this image


Looks like that worked, lets see!

Log back into the VMware Host via the web interface.

Ta da!

No alt text provided for this image


Make sure to disable SSH, or reboot to do so.

Thanks for reading

Darren Boeck

M.S., CISSP, Director of IT at Scanlan International, Inc., Sci-fi/Fantasy Author

2 年

Nice write up Roger.

要查看或添加评论,请登录

Roger Lund的更多文章

  • Welcome to the Modern Workplace

    Welcome to the Modern Workplace

    MARCH 10TH | MICROSOFT CAMPUS FARGO The nature of work has changed. Employees expect to work securely from any location…

  • Netapp 's Solidfire, How to Power the Next Generation Data Center.

    Netapp 's Solidfire, How to Power the Next Generation Data Center.

    Netapp 's Solidfire storage, is labeled as "The definitive all-flash storage for the next generation data center" What…

  • Platform9 , Openstack and Kubernetes

    Platform9 , Openstack and Kubernetes

    Need public cloud functionality without the headache? That is the focus of Platform9. Platform9 offers Openstack and…

  • Beer & Whiskey With Infinio and Arista.

    Beer & Whiskey With Infinio and Arista.

    Beer & Whiskey Tasting March 17th, 2016 11:00am - 2:00pm Cooper's Irish Pub 1607 Park Place Blvd | St. Louis Park, MN…

社区洞察

其他会员也浏览了