Identify the affected certificate

Determine whether the issue involves Machine SSL, solution user certificates, ESXi certificates or an external identity provider certificate.

Check certificate status

Review certificate details from the vCenter administration interfaces or supported appliance tools. Record subject, issuer, validity dates and thumbprint before making changes.

Check service health

If services are unavailable, verify the vCenter service status and review the vCenter and VMware certificate-manager related logs.

Validate trust relationships

After certificate changes, check whether ESXi hosts, backup tools, monitoring systems and automation clients trust the new certificate chain.

Use supported certificate procedures

Use VMware-supported certificate management workflows for the installed vCenter version. Avoid manually replacing files inside certificate stores.

Post-change validation

Confirm the vSphere Client loads, hosts remain connected, APIs respond and external integrations can authenticate.

More practical infrastructure guides

Browse the TechRunbook article library for Windows Server, VMware, Hyper-V, Azure, PowerShell and MABS troubleshooting.

Browse all articles →