Link to home
Start Free TrialLog in
Avatar of DoronAviad
DoronAviadFlag for Israel

asked on

Regenerate certificate on ESXi 4.1

Hello

I have ESXi 4.1 and I need to regenerate Certificate becuase of ESXi Host name and dns change
How can I do it ?

p.s.
In vmware web site there is an artical
http://kb.vmware.com/selfservice/microsites/search.do?cmd=displayKC&docType=kc&externalId=1008166&sliceId=1&docTypeID=DT_KB_1_1&dialogID=224246673&stateId=0 0 224248440 saying:

Generate New Certificates for the ESXi Host
The ESXi host generates certificates the first time the system is started. Under certain circumstances, you might
be required to force the host to generate new certificates. You typically generate new certificates only if you
change the host name or accidentally delete the certificate.
Procedure
1 Select Reset Customized Settings in the direct console.
2 Reboot the system to regenerate the certificates

I have entered the console from the Host itself and I can't find this option "Reset Customized Settings"

My question is how can I regenerate a new certificate for my ESXi4.1 Host
Please Advise
Avatar of Andrew Hancock (VMware vExpert PRO / EE Fellow/British Beekeeper)
Andrew Hancock (VMware vExpert PRO / EE Fellow/British Beekeeper)
Flag of United Kingdom of Great Britain and Northern Ireland image

Do you not have access to the actually Direct Console User Interface? (black and yellow screen)?

e.g. via iLO, DRAC or KVM?
Hi

Here you have all the information about certifcates for all vSphere versions

http://kb.vmware.com/kb/1008166

and also

http://kb.vmware.com/kb/4646606

Jail
and for ESXi 4.1 Page 177 Encryption and Security Certificates for ESXi

http://www.vmware.com/pdf/vsphere4/r41/vsp_41_esxi_server_config.pdf

Generate New Certificates for the ESXi Host

The ESXi host generates certificates the first time the system is started. Under certain circumstances, you might be required to force the host to generate new certificates. You typically generate new certificates only if you change the host name or accidentally delete the certificate.

Procedure

1 Select Reset Customized Settings in the direct console.

2 Reboot the system to regenerate the certificates.

There is also a procedure in the document for uploading your own Certificiate, but the easiest method would be to  Reset Customized Settings ON the direct console
Avatar of DoronAviad

ASKER

hanccocka

I have access to the direct console (black and yenllow) direct keyboard and screen connection
BestWay

I have writing in my question That I looked at the Linkes you send me..... please reread my question
and you have no option which states Reset Customized Settings? after logging in?
hanccocka

How do I see this option in the Grahy and Yellow direct interface ????
I only see option "Reset System Configuration" I don't see "Reset customized Settings"
where is that option ???
Press Function Key Number 2 (F2) to Customize System.

and then second option from the bottom, you should have Reset Customized Settings?
It will perform a Default Reset of ESXi 4.1. (all vSwitches, VMNICs) it will return to factory defaults, a bit like a fresh install.
SOLUTION
Avatar of Luciano Patrão
Luciano Patrão
Flag of Portugal image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Hi

Yes I have double checked and hanccocka is right, the option have changed, and the documentation still have the old name.

Jail
BestWay

The docuemnts about regenerating say only one option "Reset Customize Settings" (hanccocka Thanks for updating the name was change to "Reset System Configuration"

This option seems to me to extrime, for only regenerate a new Certificate to do a complite System Reset ?

I found an articale about ESXi3 with simple command line solution but it is not available in ESXi4.1

Is there another way you advise to regenrate ?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thanks you all for you great support
Have a great Day
Hi

I agreed that for to recreate only a certificate, is too much, but there is no create_certificates after ESXi 4.x, you have a script called generate_certificates.sh, but honestly I never used.

But looking at the script I think will generate the same Certificate. But I will test on my ESXi server test.

Jail
Hi

I have run the script generate_certificates.sh and restart the host, and when I try to connect again to the ESXi host with the VMware vSphere Client ask again to add the new certificate.

So running this script this will generate a new certificate that can be used.

Hope this can help.

Jail